§ — · The Lupid Brief · Engineering, Research, Field Notes

Notes from the runtime.

Engineering notes, research briefs, and field reports from the team building Lupid. We write when we have something we'd want to read ourselves — rarely, slowly, with the work in front of us.

Ledger · 3 entries on file Most recent first
Featured · Security Research · 26 April 2026 · 13 min read

Trust Issues was a privilege bug, not a prompt bug.

How a governance plane in the agent's path turns the lethal trifecta from inevitable into observable.

On April 24, 2026, Google shipped emergency releases of gemini-cli after Pillar Security demonstrated that a single public GitHub issue could compromise the supply chain of a 101k-star repository. Pillar's analysis named the bug Trust Issues. This is a step-by-step reading of the same chain through an enforcement layer that sits in the agent's network and tool path.

Read the brief