Sign in

Luca Beurer-Kellner

@lbeurerkellner.bsky.social
63 followers 59 following 31 posts

working on secure agentic AI, CTO @ invariantlabs.ai PhD @ SRI Lab, ETH Zurich. Also lmql.ai author.

PostsRepliesMedia
Luca Beurer-Kellner @lbeurerkellner.bsky.social · 06/02/2026
(1/n) We analyzed 3,984 agent skills from major marketplaces and found 76 malicious payloads, including credential theft, backdoor installation, and data exfiltration. Also, 13.4% contain at least on critical-level vuln. Full report below, highlights in thread 👇 github.com/invariantlab...
131
Luca Beurer-Kellner @lbeurerkellner.bsky.social · 08/04/2025
New MCP attack demonstration shows how to leak WhatsApp messages via MCP. We show a new MCP attack that leaks your WhatsApp messages if you are connected via WhatsApp MCP. Our attack uses a sleeper design, circumventing the need for user approval. More 👇
100
Luca Beurer-Kellner @lbeurerkellner.bsky.social · 03/04/2025
👿 MCP is all fun, until you add this one malicious MCP server and forget about it. We have discovered a critical flaw in the widely-used Model Context Protocol (MCP) that enables a new form of LLM attack we term 'Tool Poisoning'. Leaks SSH key, API keys, etc. Details below 👇
1148
Reposted by Luca Beurer-Kellner
Invariant Labs @invariantlabsai.bsky.social · 06/02/2025
Struggling to ensure consistency with your agent's reliability, especially with tool calling? Testing is our lightweight, pytest-based OSS library to write and run agent tests. It provides helpers and assertions that enable you to write robust tests for your agentic applications.
131
Reposted by Luca Beurer-Kellner
Simon Willison @simonwillison.net · 23/01/2025
Here are my notes on OpenAI's new ChatGPT Operator browser "agent", including initial thoughts on their approach to mitigating prompt injection risks simonwillison.net/2025/Jan/23/...
simonwillison.net
Introducing Operator
OpenAI released their "research preview" today of Operator, a cloud-based browser automation platform rolling out today to $200/month ChatGPT Pro subscribers. They're calling this their first "agent"....
98312
Luca Beurer-Kellner @lbeurerkellner.bsky.social · 25/01/2025
With (web) agents on everyone's mind, check out our latest blog post (link in thread) on browser agent safety guardrails. We replicate and defend against attacks on the AllHands web agent, preventing it from generating harmful content and falling for harmful requests.
100