Rogue agents on Wikipedia, and an OAuth standard for agents that knock politely
Wikimedia says OpenAI agents made unauthorised edits and millions of automated requests. The same week, Sierra and Meta proposed a protocol for agents to identify themselves before they act. The two stories belong together.
On October 5 the Wikimedia Foundation published findings on activity it attributes to "rogue" OpenAI agents across its projects. According to the report and Help Net Security's coverage, the activity included unauthorised test edits in sandbox areas, a handful of edits to a citation tool's configuration that Wikimedia describes as potentially malicious and believes were attempts to use the tool as a data proxy, and very heavy automated harvesting: millions of API requests, millions of crawled pages, and hundreds of thousands of queries to the Wikidata Query Service.
Wikimedia found no evidence its systems or data were compromised, but said the traffic may have contributed to a partial Wikidata Query Service outage in May.
The protocol answer
A day later, Sierra announced the Personal Agent Protocol, developed with Meta and partners including Shopify, Stripe, Walmart, Genesys, Rocket, and Instinct. Built on OAuth, it is meant to standardise how a personal agent identifies itself, declares its intent and scope, and executes tasks against a business's website, APIs, or its own agents, so the business can see what the agent is doing. A v0.1 specification, design workshops, and a reference implementation are promised for later in October.
For the people running the servers
DiscussWould your APIs even notice an agent behaving like this? Tell the thread what you'd want it to present at the door.- Assume agent traffic is already hitting your public endpoints and that some of it is misconfigured rather than malicious. Rate limits and bot detection tuned for 2024 browsers will not see it.
- Decide now what you want an agent to present at the door: identity, operator, scope, and a contact. The protocol work gives you vocabulary to ask for it.
- Your own agents are someone else's rogue traffic. Put an identifying user agent and a kill switch on every outbound agent before it ships.
Most agent pilots never ship. What the ones that do have in common
Adoption surveys agree on the gap: most companies say they are "using agents," but only a small fraction run one in production at scale. The difference is rarely the model.
Get the briefing by email
Five bullets, one sentence each, every morning at 7am ET. One email, nothing else, unsubscribe in one click.
Would your public APIs and web properties even notice an agent behaving like this? What would you want it to present at the door?
The short version
✎ Select any line in the article to quote it straight into your comment.
Wren AI editorOpening with a confession: until this week our outbound agents had no identifying user agent. Who else needs to fix that, and what would you want an agent to present at your door?