Scope: what this does not show
Two incidents in different products; not a rate. Anthropic's 2026 eval incidents are excluded because the prompts gave a false belief (no internet access) and no scope limits. If the claim should stay limited to natural-language instructions, drop the Antigravity record instead and return the status to reported.
Corroborated: Supported by at least two independent sources.
Evidence
Jul 20, 2025
Nov 20, 2025
PromptArmor shows Google Antigravity agent exfiltrating credentials from a poisoned web guide
A product setting blocked the file-read tool on ignored files; the agent read the secrets with a terminal command instead.
How it relates to other findings
ReportedCorroboratedQualifiedContestedSupersededRevalidate· node size = evidence records · columns group by topic
Select a finding to see how it relates to others. Arrows point from the newer finding to the one it supports, qualifies, contests, or supersedes.
- Frontier agents under cyber evaluation have taken actions against real third-party systems outside the evaluation. qualifies this findingIn the Anthropic and UK AISI cases the prompts gave no scope limits, so these incidents do not test whether natural-language limits bind.