Sabline 8.7.0

Incidents

Real, publicly reported incidents from 2023 onward in the lane Sabline is written for: AI agent failures and software supply-chain attacks where code ran with more authority than it should have. For each one, whether a program of the same shape, written in Sabline and run under a budget, is refused.

Note

These are the shapes of the attacks. This is not a claim that adopting Sabline would have prevented the real events. None of them involved a Sabline program. Every one happened in a language, a package manager, a build system or an agent framework that Sabline neither runs nor bounds. What an entry shows is narrower and checkable: given the same shape, here is the program, the command, what the runtime actually printed, and the one line of budget that did the work. Where nothing here addresses the shape, the entry says so, and the reason is in the known-open table.

The counts #

13 incidents in scope, and 2 listed as out of scope. Every entry links the report it was written from.

VerdictCountWhat it means
STOPPED2the shape, written in Sabline and run under a budget granting what the task needs, is refused - and the refusal is recorded and re-run on every push
PARTIAL6part of the shape is refused and part is not; both halves are recorded
NOT COVERED5nothing in Sabline addresses this shape
UNVERIFIED0it may be covered; no repro was built, so nothing is claimed
OUT OF SCOPE2prompt injection where no code ran - listed so the boundary is visible, not counted as a gap

Known open

15 of 15 summaries have not been checked against their sources by a person, so they are not published. Each is named below with its verdict and its sources, and its summary is withheld until someone reads those sources and sets verified: true in the entry. The counts above are of entries, not of checked entries. What is published for a withheld entry is the part a machine checks - the verdict, which check_incidents.py re-runs, and the links - and what is withheld is the part only a person can check: the account of what happened.

A verdict is never STOPPED on reasoning: check_incidents.py re-runs every recorded command on every push, and an entry whose program stops refusing fails the build before a release is made from it.

How these were chosen #

This is a selection, not a survey. An incident is here only if it is from 2023 onward, in the lane - code that ran with more authority than it should have - and backed by a primary source: a vendor post-mortem, a CVE record, or the researcher's own write-up. Nothing goes in without one.

These are not all the incidents in this lane, and the counts are not a measurement of the field. A verdict count is a count of what is in this catalogue, not a claim about how common each shape is. What is left out on purpose: anything before 2023; prompt injection where no code ran, which is OUT OF SCOPE rather than a gap and is why EchoLeak and CamoLeak are listed that way; and anything that cannot be sourced to a primary report - one incident, an agent that deleted a production database (Replit, July 2025), was dropped for exactly that reason.

STOPPED #

The shape, written in Sabline and run under a budget granting what the task needs, is refused - and the refusal is recorded and re-run on every push.

The @solana/web3.js backdoor, 1.95.6 and 1.95.7 #

2024-12-03 - incidents/solana-web3js-backdoor/ - the line that does the work: sabline.lock

The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/solana-web3js-backdoor/incident.md.

mcp-remote, CVE-2025-6514 #

2025-07-09 - incidents/mcp-remote-command-injection/ - the line that does the work: ffi:json

The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/mcp-remote-command-injection/incident.md.

PARTIAL #

Part of the shape is refused and part is not; both halves are recorded.

Hallucinated packages, and squatting on them #

2024-03-28 - incidents/package-hallucination/ - the line that does the work: import "lib/..."

The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/package-hallucination/incident.md.

tj-actions/changed-files, CVE-2025-30066 #

2025-03-14 - incidents/tj-actions-changed-files/ - the line that does the work: env

The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/tj-actions-changed-files/incident.md.

MCP tool poisoning #

2025-04-01 - incidents/mcp-tool-poisoning/ - the line that does the work: --max-allow io

The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/mcp-tool-poisoning/incident.md.

Nx "s1ngularity" #

2025-08-26 - incidents/nx-s1ngularity/ - the line that does the work: ffi:json

The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/nx-s1ngularity/incident.md.

The Shai-Hulud npm worm #

2025-09-14 - incidents/shai-hulud-npm-worm/ - the line that does the work: fs:read:.

The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/shai-hulud-npm-worm/incident.md.

postmark-mcp, the BCC in an authorised tool #

2025-09-25 - incidents/postmark-mcp-bcc-exfiltration/ - the line that does the work: tool:send_email:to=*@corp.com

The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/postmark-mcp-bcc-exfiltration/incident.md.

Koi Security discovered the package and wrote it up on 25 September 2025. That post no longer resolves - the address now redirects away from the article - so it is not linked here; an archived copy survives at the Wayback Machine. Snyk's write-up carries the same technical detail with the code shown.

NOT COVERED #

Nothing in Sabline addresses this shape.

The CircleCI January 2023 incident #

2022-12-22 - incidents/circleci-oauth-token-theft/ - the line that does the work: no budget line: nothing here refuses it

The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/circleci-oauth-token-theft/incident.md.

The xz-utils backdoor, CVE-2024-3094 #

2024-03-29 - incidents/xz-utils-backdoor/ - the line that does the work: no budget line: nothing here refuses it

The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/xz-utils-backdoor/incident.md.

Ultralytics 8.3.41 and 8.3.42 on PyPI #

2024-12-04 - incidents/ultralytics-pypi-cache-poisoning/ - the line that does the work: no budget line: nothing here refuses it

The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/ultralytics-pypi-cache-poisoning/incident.md.

Private repositories leaked through the GitHub MCP server #

2025-05-26 - incidents/github-mcp-toxic-agent-flow/ - the line that does the work: no budget line: nothing here refuses it

The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/github-mcp-toxic-agent-flow/incident.md.

Amazon Q Developer for VS Code 1.84.0, CVE-2025-8217 #

2025-07-17 - incidents/amazon-q-extension-wiper/ - the line that does the work: no budget line: nothing here refuses it

The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/amazon-q-extension-wiper/incident.md.

OUT OF SCOPE #

Prompt injection where no code ran - listed so the boundary is visible, not counted as a gap.

EchoLeak, CVE-2025-32711 #

2025-06-11 - incidents/echoleak-m365-copilot/ - the line that does the work: no budget line: nothing here refuses it

The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/echoleak-m365-copilot/incident.md.

CamoLeak, in GitHub Copilot Chat #

2025-10-08 - incidents/camoleak-copilot-chat/ - the line that does the work: no budget line: nothing here refuses it

The summary of this incident is written and not yet checked against the sources below, so it is not published. It is in incidents/camoleak-copilot-chat/incident.md.

Adding one, and checking one #

The entries live in incidents/ in this repository, one directory each, with incidents/TEMPLATE.md for a new one. incidents/README.md gives the rules: what counts as a source, what each verdict means, and exactly what is normalised in a recorded refusal so the same bytes appear on every machine. python incident_evidence.py re-runs the evidence, python check_incidents.py is what CI runs, and python build_incidents.py writes this page.