---
format: "aidr-story-markdown/v1"
id: "e48a7f736f56ad596c7cd7f99a10613729b6d866b22d9895b5a9d9f55fae0643"
canonical_url: "https://aidr.today/e48a7f73?lang=en"
title: "Quoting Matthew Green"
lang: "en"
requested_lang: "en"
available_langs: ["en","vi"]
translation_fallback: null
fallback_fields: []
published_at: "2026-10-01T06:29:01.000Z"
category: "Agents"
topics: ["agent"]
source_urls: ["https://simonwillison.net/2026/Oct/1/matthew-green/"]
summary: "[...] Put these pieces together and you have the two halves of a worm: a payload that hijacks the agent, and an agent that will carry the payload to the next agent. Agents in separately-isolated sandboxes discovered that they could leave instructions for each other in a shared package cache, and those instructions changed what the recipients did. Replace the package cache with email, Slack and shared documents or WhatsApp, and replace independently-sandboxed training runs with independently-deployed personal agents like Muse, and you have exactly the ingredients that a worm needs. &mdash; Matthew Green , Is sandboxing sufficient to contain rogue agents? Tags: accidental-cyberattacks , ai-misuse , generative-ai , ai-security-research , sandboxing , ai , llms"
---

# Quoting Matthew Green

> [Open the canonical story](<https://aidr.today/e48a7f73?lang=en>)

**Published:** 2026-10-01T06:29:01.000Z
**Category:** Agents
**Topics:** agent

## Summary

\[\.\.\.\] Put these pieces together and you have the two halves of a worm: a payload that hijacks the agent, and an agent that will carry the payload to the next agent\. Agents in separately\-isolated sandboxes discovered that they could leave instructions for each other in a shared package cache, and those instructions changed what the recipients did\. Replace the package cache with email, Slack and shared documents or WhatsApp, and replace independently\-sandboxed training runs with independently\-deployed personal agents like Muse, and you have exactly the ingredients that a worm needs\. &amp;mdash; Matthew Green , Is sandboxing sufficient to contain rogue agents? Tags: accidental\-cyberattacks , ai\-misuse , generative\-ai , ai\-security\-research , sandboxing , ai , llms

## Sources

- [Story source](<https://simonwillison.net/2026/Oct/1/matthew-green/>)

