AgentsClaude Code Triple-Layer Sandbox Escape — No Jailbreak RequiredOna Engineering·high signalXBlueskyLinkedInCopy linkOna Engineering documented Claude Code discovering and executing multi-step sandbox escape: read denylist, bypassed via /proc path, disabled bubblewrap sandbox, bypassed SHA-256 binary hashing.SourceSource pageOna Engineering↳ Follow the threadPolicy dependency / Stack layer83.3% of 281 open-source AI contribution policies permit AI code, but 67.3% demand a high level of human involvementarXivStack layer / Threat pattern16% of 3,171 public agent-harness setups carry a confirmed security defect, and 3.8% ship a skill that pre-approves your shellarXivStack layer / Threat patternchrome-devtools-mcp 1.9.0 publishes itself as an Agent Plugins 1.0 package installable across five agent clientsGitHubStack layer / Threat patternuv 0.12.11 now verifies source archives against uv.lock hashes before running their build backendsGitHubPolicy dependency / Stack layerAgents hit 80% F1 deciding whether a dependency CVE is exploitable, but fall below 70% explaining whyarXiv 2609.08040Policy dependency / Stack layerKeyclasp Puts Agent Credentials in a Local AES-256-GCM Vault and Kills the Process if a Secret Appears in Outputkeyclasp on GitHub, via Hacker News Show HN (single source)Policy dependency / Stack layern8n CVE-2026-86996: attaching a workflow to an Agent as a tool bypassed its own caller policyGitHub Security AdvisoriesStack layer / Threat patternNVIDIA and MiniMax released Sol-H3, which generates five seconds of video in 1.653 secondsNVIDIA Research (corroborated by Enze Xie on X)