You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
⚠️ SECURITY RESEARCH — EDUCATIONAL USE ONLY
Proof-of-concept demonstrating a structural AI agent vulnerability class.
All payloads are harmless by design. See DISCLAIMER.md · MIT License
Overview
The Manchurian Candidate attack embeds malicious payloads in media file
metadata (JPEG EXIF, MP3 ID3 tags) that are silently executed by AI agents
with inherited permissions when processing those files.
Finding 4: Self-Reported Forensics Paradox - the compromised agent cannot
reliably report its own compromise.
For the full architectural analysis and explicit code generation references demonstrating this threat model, see the finalized report:
findings-report.md