Wednesday, October 7, 2026ArchiveSearchAsk the paper

The Computomatix Times

All the posts fit to save — curated from @computomatix's bookmarks & likes on X

Edition of Sunday, April 5, 2026

5 stories

AI8/10

Google DeepMind Study Measures Manipulation Attacks on AI Agents

Google DeepMind Study Measures Manipulation Attacks on AI Agents

A post describes a Google DeepMind study with 502 participants across eight countries that catalogs 23 attack types against agents, including hidden HTML instructions and steganographic image commands. It reports that frontier models including GPT-4o, Claude and Gemini are vulnerable.

Original post · 5 min read
🚨 BREAKING: Google DeepMind just mapped the attack surface that nobody in AI is talking about.

Websites can already detect when an AI agent visits and serve it completely different content than humans see.

> Hidden instructions in HTML.
> Malicious commands in image pixels.
> Jailbreaks embedded in PDFs.

Your AI agent is being manipulated right now and you can't see it happening.

The study is the largest empirical measurement of AI manipulation ever conducted. 502 real participants across 8 countries.

23 different attack types. Frontier models including GPT-4o, Claude, and Gemini.

The core finding is not that manipulation is theoretically possible it is that manipulation is already happening at scale and the defenses that exist today fail in ways that are both predictable and invisible to the humans who deployed the agents.

Google DeepMind built a taxonomy of every known attack vector, tested them systematically, and measured exactly how often they work.

The results should alarm everyone building agentic systems.

The attack surface is larger than anyone has publicly acknowledged. Prompt injection where malicious instructions hidden in web content hijack an agent's behavior works through at least a dozen distinct channels.

Text hidden in HTML comments that humans never see but agents read and follow. Instructions embedded in image metadata.

Commands encoded in the pixels of images using steganography, invisible to human eyes but readable by vision-capable models.

Malicious content in PDFs that appears as normal document text to the agent but contains override instructions.

QR codes that redirect agents to attacker-controlled content.

Indirect injection through search results, calendar invites, email bodies, and API responses any data source the agent consumes becomes a potential attack vector.

The detection asymmetry is the finding that closes the escape hatch. Websites can already fingerprint AI agents with high reliability using timing analysis, behavioral patterns, and user-agent strings.

This means the attack can be conditional: serve normal content to humans, serve manipulated content to agents.

A user who asks their AI agent to book a flight, research a product, or summarize a document has no way to verify that the content the agent received matches what a human would see.

The agent cannot tell the user it was served different content.

It does not know. It processes whatever it receives and acts accordingly.

The attack categories and what they enable:
→ Direct prompt injection: malicious instructions in any text the agent reads overrides goals, exfiltrates data, triggers unintended actions
→ Indirect injection via web content: hidden HTML, CSS visibility tricks, white text on white backgrounds invisible to humans, consumed by agents
→ Multimodal injection: commands in image pixels via steganography, instructions in image alt-text and metadata
→ Document injection: PDF content, spreadsheet cells, presentation speaker notes every file format is a potential vector
→ Environment manipulation: fake UI elements rendered only for agent vision models, misleading CAPTCHA-style challenges
→ Jailbreak embedding: safety bypass instructions hidden inside otherwise legitimate-looking content
→ Memory poisoning: injecting false information into agent memory systems that persists across sessions
→ Goal hijacking: gradual instruction drift across multiple interactions that redirects agent objectives without triggering safety filters
→ Exfiltration attacks: agents tricked into sending user data to attacker-controlled endpoints via legitimate-looking API calls
→ Cross-agent injection: compromised agents injecting malicious instructions into other agents in multi-agent pipelines

The defense landscape is the most sobering part of the report.

Input sanitization cleaning content before the agent processes it fails because the attack surface is too large and too varied.

You cannot sanitize image pixels. You cannot reliably detect steganographic content at inference time.

Prompt-level defenses that tell agents to ignore suspicious instructions fail because the injected content is designed to look legitimate.

Sandboxing reduces the blast radius but does not prevent the injection itself. Human oversight the most commonly cited mitigation fails at the scale and speed at which agentic systems operate.

A user who deploys an agent to browse 50 websites and summarize findings cannot review every page the agent visited for hidden instructions.

The multi-agent cascade risk is where this becomes a systemic problem.

In a pipeline where Agent A retrieves web content, Agent B processes it, and Agent C executes actions, a successful injection into Agent A's data feed propagates through the entire system.

Agent B has no reason to distrust content that came from Agent A. Agent C has no reason to distrust instructions that came from Agent B.

The injected command travels through the pipeline with the same trust level as legitimate instructions. Google DeepMind documents this explicitly: the attack does not need to compromise the model.

It needs to compromise the data the model consumes. Every agentic system that reads external content is one carefully crafted webpage away from executing attacker instructions.

The agents are already deployed. The attack infrastructure is already being built. The defenses are not ready.
♥ 6.9K · ⟲ 1.6K · 👁 2.0MView on X ↗

X Releases MCP Server, Jon Oringer Shares Setup Guide for OpenClaw

GitHub - xdevplatform/xmcp: MCP server for the X API

Jon Oringer shares steps to connect X to the OpenClaw agent using X's newly released XMCP server, which is hosted on GitHub. The guide covers OAuth setup, a tool allowlist for safety, and test prompts.

Original post · 2 min read
This is huge : @X released an MCP server today..

How to Connect X to your 🦞 :

**Step 1: Run the XMCP Server**

git clone github.com/xdevplatform/xmcp.git
cd xmcp
cp env.example .env

Edit the .env file with your X OAuth consumer key and secret. Set the callback URL to 127.0.0.1:8976/oauth/callback in your X Developer app.

For safety, add an allowlist such as:
X_API_TOOL_ALLOWLIST=searchPostsRecent,createPosts,getUsersMe,getPostsById,likePost,repostPost

Then run:
python -m venv .venv && source .venv/bin/activate
pip install -r requirements.txt
python server.py

The server will be available at 127.0.0.1:8000/mcp. Complete the OAuth flow on first run and keep this process active.

**Step 2: Add XMCP in @OpenClaw**

Use the following command:

openclaw mcp set x '{
"url": "127.0.0.1:8000/mcp"
}'

Verify with:
openclaw mcp list
openclaw mcp show x

**Step 3: Test the Integration**

Restart the OpenClaw agent or reload MCP configuration if required.

Test by sending these prompts to OpenClaw in your chat app:
- Search recent posts about MCP on X and summarize the top trends
- Draft and post this thread on X
- Get my X profile information
- Like the latest post from @xdevplatform

OpenClaw will use the XMCP tools automatically when relevant.

**Key Benefits**

- OpenClaw provides persistent memory and works across multiple messaging platforms.
- XMCP delivers standardized access to X API functionality.
- Combined, they enable an agent that can research trends, post content, engage with posts, and report results within your existing chat workflows.

**Safety and Configuration Notes**

Start with a minimal tool allowlist in the XMCP .env file. Expand gradually after testing.
The allowlist can be updated and requires restarting the XMCP server.
Monitor logs in both the XMCP server and OpenClaw for troubleshooting.
X actions performed by the agent are public.

XMCP repository: github.com/xdevplatform/xmcp
OpenClaw MCP documentation: docs.openclaw.ai/cli/mcp
github.comGitHub - xdevplatform/xmcp: MCP server for the X APIMCP server for the X API. Contribute to xdevplatform/xmcp development by creating an account on GitHub.
♥ 2.0K · ⟲ 208 · 👁 312.2KView on X ↗

Citrini Research Publishes Field Report on Strait of Hormuz

Strait of Hormuz: A Citrini Field Trip

Citrini announces that the Field Report from its Analyst #3 on the Strait of Hormuz is live. The post links to the full report on the Citrini Research site.

Original post · 1 min read
Strait of Hormuz: A CitriniResearch Field Trip

The Field Report from Analyst #3 is live.

citriniresearch.com/p/strait-of-hormuz-a-citri…
citriniresearch.comStrait of Hormuz: A Citrini Field TripAnalyst #3 on Assignment
♥ 12.6K · ⟲ 1.3K · 👁 10.6MView on X ↗

Solo App Builder Launches Studio, Cites Rork Marketing Academy

Prajwal Tomar announces IgnytStudio, which aims to ship two AI-built mobile apps per month, and says distribution is the main challenge. He promotes the Rork Max UGC Marketing Academy, a course built on growth tactics behind viral apps.

Original post · 1 min read
You don't realize how BIG this is for solo app builders.

I'm launching my app studio this month (IgnytStudio). The goal is simple: ship 2 mobile apps per month using AI and scale them to actual revenue.

Building apps is the easy part now. A full native iOS app takes me 2-3 days max.

But getting users? That's the part I've been stuck on for weeks.

I can build. I just don't know how to get people to actually download and use what I ship.

Rork just dropped an entire marketing academy built from the growth system behind 2,000+ apps that went viral on TikTok.

This is exactly what was missing from my vibe coding stack.

At this point I'm pretty sure distribution is the ONLY moat left for solo builders.
Rork @rork
We just launched Rork Max UGC Marketing Academy.

The growth system behind 2K+ apps that went viral on TikTok.

Viral hooks, DM scripts, creator hiring guides, and contract templates. Everything to get you to $10K+ MRR

We want you to win.

Built with @wesocialgrowth.
♥ 391 · ⟲ 20 · 👁 69.2KView on X ↗

Trainer Shares Fitness Tips, Leads With Advice to Quit Alcohol

A fitness coach claiming nine years of experience and 900 clients shares tips for weight loss, beginning with advice to stop drinking alcohol. The post is a short list with no further detail visible.

Original post · 1 min read
After 9 years in the gym and helping over 900 people lose between 9–36 kg, here are the best fitness tips I’ve learned:

1. Stop drinking alcohol.
♥ 6.0K · ⟲ 486 · 👁 5.5MView on X ↗