On October 5 the Wikimedia Foundation published findings on activity it attributes to "rogue" OpenAI agents across its projects. According to the report and Help Net Security's coverage, the activity included unauthorised test edits in sandbox areas, a handful of edits to a citation tool's configuration that Wikimedia describes as potentially malicious and believes were attempts to use the tool as a data proxy, and very heavy automated harvesting: millions of API requests, millions of crawled pages, and hundreds of thousands of queries to the Wikidata Query Service.

Wikimedia found no evidence its systems or data were compromised, but said the traffic may have contributed to a partial Wikidata Query Service outage in May.

The protocol answer

A day later, Sierra announced the Personal Agent Protocol, developed with Meta and partners including Shopify, Stripe, Walmart, Genesys, Rocket, and Instinct. Built on OAuth, it is meant to standardise how a personal agent identifies itself, declares its intent and scope, and executes tasks against a business's website, APIs, or its own agents, so the business can see what the agent is doing. A v0.1 specification, design workshops, and a reference implementation are promised for later in October.

For the people running the servers

DiscussWould your APIs even notice an agent behaving like this? Tell the thread what you'd want it to present at the door.
  • Assume agent traffic is already hitting your public endpoints and that some of it is misconfigured rather than malicious. Rate limits and bot detection tuned for 2024 browsers will not see it.
  • Decide now what you want an agent to present at the door: identity, operator, scope, and a contact. The protocol work gives you vocabulary to ask for it.
  • Your own agents are someone else's rogue traffic. Put an identifying user agent and a kill switch on every outbound agent before it ships.