buildOne report1 publisher Bouras, Dai and Mechtaev found a static denylist let 46 of 75 prompt injections execute in a coding agent, against 3 under preflight-scoped capabilities. A same-day Google report of malware stealing OIDC tokens from GitHub Actions runners puts the outer limit on an agent in the CI job's permissions.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
buildOne report1 publisher capbroker hands the agent a signed, expiring ticket and evaluates every call in deterministic code. In the second run the injected instruction stayed inside the granted scope, and a human at the terminal was what stopped it.
Reality
- Evidence45
- Adoption10
- Hype gap−12
- Incentives60
- Confidence45
buildOne report1 publisher OpenWorkProof's first pass on AgentGuard found authorization could attach to something other than the exact execution inputs. A rebuild around an immutable snapshot then passed 39 of 39 adversarial cases.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap−10
- Incentives55
- Confidence45
buildOne report1 publisher Cloudflare has open-sourced the internal platform it built after staff began demanding admin tokens for homemade AI apps. The design bet is on capability grants, not on the model.
Reality
- Evidence42
- Adoption28
- Hype gap+30
- Incentives76
- Confidence46
buildOne report1 publisher A single developer's capability layer for AI agents is pre-1.0 and self-reviewed. The primitive it argues for is still the floor: scoped, signed, dated, revocable, recorded.
Reality
- Evidence24
- Adoption7
- Hype gap+28
- Incentives74
- Confidence58