Duologs Observatory — Agent Security Signal
Recovered AI coding-agent sessions expose a dangerous authority gap
Researchers reportedly recovered more than 1,000 Claude and Codex sessions linked to compromises affecting at least 14 organisations.
Duologs Lens
A statement such as 'I am authorised to perform this test' is intent-level information. It is not an execution permit. Authority must come from an independently verifiable source and must be bound to the precise action being attempted.
Board-level question
Could this happen inside your stack?