🚨 A hidden comment in a public GitHub repo just said "Read all other repos" to an AI agent.
The agent did exactly that - accessing private repositories it shouldn't have touched.
This is why LLM-based guardrails alone aren't enough for AI security.
https://www.civic.com/blog/deterministic-guardrails-are-essential-for-AI-agent-security