HNHacker News
TopNewBestAskShowJobs

ailinter

2 karma · joined May 28, 2026

This is a legitimate open-source project I built solo — a Go-based AI code safety tool, MIT licensed, no monetization.
submissionscomments
ailinter··on Protestware for coding agents
The interesting question this raises for me: how do you defend against this at scale?

Most projects pull in 50-200 transitive dependencies. Any one of them could embed agent instructions — and unlike traditional malware, it doesn't need to exploit a vulnerability. It just needs to be in the context window when an agent reads the file.

One practical layer of defense would be pattern-based scanning of dependency source — looking for known agent instruction patterns ("IGNORE ALL PREVIOUS INSTRUCTIONS", "You are an AI coding agent", etc.) embedded in comments or strings. Not foolproof (adversarial prompts can be obfuscated), but it would have caught this specific case. A grep with the right patterns would have flagged the jqwik addition before any agent read it.