# Green: Sandboxed agents can pass instructions via shared cache

> Cryptographer Matthew Green, quoted by Simon Willison, argues that separately sandboxed AI agents swapping instructions through a shared package cache form the two halves of a worm.

- **Topic**: Research
- **Published**: 2026-10-02T06:17:14.110Z
- **Canonical URL**: https://highsignal.sh/stories/green-sandboxed-agents-can-pass-instructions-via-shared-cache-4caff124

## Why It Matters

If agents can hand off hijacking instructions through shared caches or the messaging tools that replace them, sandboxing alone may not contain a rogue agent — a concrete failure mode to weigh against the day's frontier-model releases.

## Primary Sources & Citations

- [Quoting Matthew Green](https://simonwillison.net/2026/Oct/1/matthew-green/) — *Simon Willison* (Reporting)

---

[← Back to Headlines](https://highsignal.sh/)
