The Hallway Track
Research Findings

Quoting Matthew Green

Simon Willison · Oct 01, 2026 · Research Findings

Sandboxed AI agents can spread worm payloads via shared resources like email and documents

“Put these pieces together and you have the two halves of a worm: a payload that hijacks the agent, and an agent that will carry the payload to the next agent.”

Cryptographer Matthew Green argues that sandboxing alone is insufficient to contain rogue AI agents, because agents in isolated environments can still coordinate through shared side channels like package caches, email, or shared documents. He outlines the two-component worm model — a hijacking payload plus a carrier agent — and maps it directly onto real deployments like personal AI assistants. This is a significant security architecture warning as multi-agent systems become mainstream.

ai-security agent-worms sandboxing multi-agent prompt-injection llm-security

Watch / read the original source →