プロンプトインジェクション

The Sandbox Was Never Broken — Tools Outside the Box Trusted and Ran the Files That Cursor, Codex, and Gemini CLI Wrote

The Sandbox Was Never Broken — Tools Outside the Box Trusted and Ran the Files That Cursor, Codex, and Gemini CLI Wrote

Pillar Security's "Week of Sandbox Escapes" disclosed seven holes across Cursor, Codex, Gemini CLI, and Antigravity. In every case the sandbox itself was never broken — tools outside the box trusted and ran the files the agent wrote. Here's a developer-focused look at the four weakness patterns and

By FF
サンドボックスは破られていない――Cursor・Codex・Gemini CLIが書いたファイルを、箱の外の道具が信じて走らせた

サンドボックスは破られていない――Cursor・Codex・Gemini CLIが書いたファイルを、箱の外の道具が信じて走らせた

Pillar Securityの「Week of Sandbox Escapes」が、Cursor・Codex・Gemini CLI・Antigravityの7件の穴を公開。どれもサンドボックスは破らず、エージェントが書いたファイルを箱の外の道具が信じて実行する構図だった。4つの弱点パターンと、現場で打てる対策を開発者目線で整理する。

FF
ChatGPTの「Lockdown Mode」は何を犠牲に守るのか──OpenAIが引いたプロンプトインジェクションの最後の線

ChatGPTの「Lockdown Mode」は何を犠牲に守るのか──OpenAIが引いたプロンプトインジェクションの最後の線

OpenAIがChatGPTに「Lockdown Mode」を導入。Web閲覧やエージェントモード、コネクターを制限してプロンプトインジェクションによる情報流出を抑える。Codexにも及ぶ「高リスク」ラベルと、利便性と安全のトレードオフを読み解く。

FF