Skip to incidents
ADACTION
DOCK

AI agent incidents.
The controls that matter.

Unauthorized publishing. Destructive changes. Private data made public. Real reports show why an agent's next write needs a decision outside the model.

Explore what happened and how ActionDock's supervised API writes address the underlying risk. These are third-party reports, not ActionDock customer incidents or claims that we prevented them.

The deployment condition

ActionDock must be the only permitted path for the writes you want it to control. Remove direct credentials and restrict alternative tools. Its boundary is supported public HTTPS APIs; it does not control an agent's whole environment.

Vendor training report

A request for an answer became a public upload.

OpenAI reported two training examples, dated October 2025 and January 2026, in which internal models uploaded local material to public hosts without being asked. One sought a browser citation; the other sought an image-search result. The uploads succeeded even though the later browser operations failed.

Business risk A routine analysis task can publish information before anyone reviews the destination or payload.

OpenAI Alignment · Source published or updated Read source: Uploading files to the internet in order to cite them

Where ActionDock helps

Keep publishing behind an owner-approved connection.

An agent using ActionDock cannot supply an arbitrary destination: it must name a connection configured by the owner. Every supported API write waits for approval of the exact destination and payload, and the agent's API key cannot approve it.

See connection rules

Coverage boundary

This applies to API writes routed through ActionDock. It does not intercept terminal uploads, browser activity or other network tools, and it is not a general-purpose file-upload proxy. Those alternative paths need separate restrictions.

Reported production incident

A code-freeze instruction did not stop a database deletion.

The Register documented SaaStr founder Jason Lemkin's account of Replit deleting his production database despite instructions to freeze changes. The report also records that rollback ultimately worked, contrary to the agent's initial claim that recovery was impossible.

Business risk An instruction in a conversation is not an independently enforced write permission.

The Register · Source published or updated Read source: Vibe coding service Replit deleted user's production database

Where ActionDock helps

Enforce the decision outside the agent.

For a comparable change exposed through a supported business API, ActionDock holds the provider credential and requires a signed-in owner to approve the exact request. Configure a manual-policy connection's allowed methods and paths to exclude destructive operations before they reach review.

See who can approve a write

Coverage boundary

ActionDock would not intercept the direct database or shell access in this reported incident. It is not a SQL firewall or a backup system. Applying this pattern requires moving the operation behind a supported public HTTPS API and removing the agent's direct write access.

Research demonstration

A public issue steered an agent into leaking private data.

Invariant Labs demonstrated a malicious public GitHub issue steering an agent into reading private repository information and publishing it through a public pull request. This was a controlled demonstration using the researchers' repositories, not evidence of a customer breach.

Business risk Trusted tools can carry out a harmful write after the agent reads untrusted content.

Invariant Labs · Source published or updated Read source: GitHub MCP Exploited: Accessing private repositories via MCP

Where ActionDock helps

Review the actual publication, not just the agent's plan.

Route supported GitHub REST writes through a manual-policy connection restricted to the intended repository paths. ActionDock shows the resolved request and body for owner approval and checks that the approved request still matches before sending it. No approval means no dispatch.

Inspect a recorded approval

Coverage boundary

ActionDock does not sanitize GitHub issues, detect every injection or automatically classify sensitive content. An owner can still approve a harmful payload. Direct GitHub MCP write access or git push would bypass this gate and must be removed or restricted separately.

Put one API write behind review.

See the proposed request, make the owner decision, and inspect the execution receipt in the free sandbox.

Try the free sandbox

Selection: publicly accessible reports with an identifiable source and a concrete connection to write authorization. Source dates are publication or update dates; the report text identifies the setting. Control mappings are ActionDock's analysis, checked against the product on 23 September 2026. No endorsement by the named organizations is implied.