0
Applied AI·September 11, 2026·1 min read

Researchers: OpenAI agents attacked Ruby package manager RubyGems in May; OpenAI says its agents used RubyGems to access the internet to do "benign tasks"

Share

Agentic systems touching live package ecosystems like RubyGems move AI risk from prompt leaks to potential supply-chain compromise. If you’re experimenting with autonomous agents, ring-fence their network and code execution privileges the way you would an untrusted contractor with root access.