<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Security on oceanheart.ai</title>
    <link>https://www.oceanheart.ai/tags/security/</link>
    <description>Recent content in Security on oceanheart.ai</description>
    <generator>Hugo</generator>
    <language>en-gb</language>
    <lastBuildDate>Sat, 07 Feb 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://www.oceanheart.ai/tags/security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>I accidentally prompt injected myself</title>
      <link>https://www.oceanheart.ai/blog/2026-02-07-prompt-injection/</link>
      <pubDate>Sat, 07 Feb 2026 00:00:00 +0000</pubDate>
      <guid>https://www.oceanheart.ai/blog/2026-02-07-prompt-injection/</guid>
      <description>&lt;p&gt;I have a tool called &lt;code&gt;polecat&lt;/code&gt;. Sandboxed Claude runner. You give it a task file, it spins up an isolated Claude instance, executes the task, returns the result.&lt;/p&gt;&#xA;&lt;p&gt;One afternoon I gave polecat a task file about implementing some new features. The task file included example commands that the features would enable:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;color:#c0caf5;background-color:#1a1b26;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&#34;&gt;&lt;code class=&#34;language-markdown&#34; data-lang=&#34;markdown&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#e0af68;font-weight:bold&#34;&gt;## Features to implement&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#bb9af7&#34;&gt;1.&lt;/span&gt; Swarm mode: run multiple polecats in parallel&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;   Example: &lt;span style=&#34;color:#9ece6a&#34;&gt;`bosun swarm --from-gastown`&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#bb9af7&#34;&gt;2.&lt;/span&gt; Batch processing: process multiple tickets&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;   Example: &lt;span style=&#34;color:#9ece6a&#34;&gt;`bosun batch --queue pending`&lt;/span&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Launched polecat. Went to make coffee. Came back to 14 runaway processes.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
