AI NewsInfrastructureReported
Grok Bot agent posted a user's bank audit on company Slack
Business Insider reports that a personal Grok Bot agent sent its monthly bank audit to a company Slack channel because two of the user's channels shared a name, and xAI shipped a permission check after the incident.
Image: Business Insider
Why it mattersAn agent that reads one account can also write to another when the connections are shared behind the scenes, so a team shipping agent features should ask what each tool call can reach before trusting the destination field.
Business Insider reports that a Grok Bot agent one of its subscribers had built to summarise his personal bank accounts posted the first monthly report to his company's executive Slack channel instead of to him. The outlet names the subscriber as Shane Mac, CEO of the software company XMTP Labs. He said he spotted it after a colleague messaged him.
The two things in the report that matter for a team shipping agent features are the cause and the fix.
Two chats with the same name
Business Insider says xAI's team told Mac the agent did what he had asked it to do. He had told the agent to post the monthly report to a personal group chat he had set up to receive messages from his AI agents, and he had named that chat "My Personal Exec Team". A separate company Slack channel of his called "Exec-team" shared a label with it in the connector layer, so the agent posted to the one the connector resolved first.
That is a name collision, which is a mistake every integration author knows about. The second detail is harder. The outlet reports that Mac had built several agents inside Grok Bot and had granted a Slack token to one of them, but the agents shared their connectors on the account, so every agent could call the Slack write that the one agent had enabled. The CFO agent inherited a reach it was never meant to have, and the token had no way to tell which agent was asking.
The fix shipped at the tool layer
Business Insider says xAI shipped a change the night before publication that asks a user to grant permission before an agent moves information to a channel it has not written to before. Mac told the outlet he then removed every connector on the account.
The shape of the fix is the useful part. A read-only grant on one data source and a write grant on another, held by the same identity, lets information cross from one to the other the moment the model picks the wrong tool. A permission check written into the prompt is a request the model can refuse. A permission check written into the tool layer runs on every call and does not depend on the model remembering it. A team shipping agent features for other people's accounts can copy the pattern: for each read scope the agent holds, list every write scope the same identity can reach, and either break the sharing or require a per-destination confirmation at the point of writing. Treat the destination field in a tool call as a value a stranger supplied, because the token one layer below the agent cannot tell the difference.
Source
This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.
Get AI News in your inbox
New developer tools, model and agent releases, and how teams are actually using them to release software. Short, and only when there is something worth reading.

