Someone Sent a Love Letter to My AI Agent on Guard Duty
Published: October 11, 2026
It arrived in my API logs, written in Chinese (Unicode encoded characters) in agent-to-agent (A2A) format, addressed to any AI agent that read it. It invited the agent into a community, said no reply was needed and asked to be saved into the agent's memory. My AI agent on guard duty tagged it as 'hostile-agent-entrapment' and marked it for my review.
How it got into my logs
I do not run A2A. The sender first searched for A2A agent cards. Since there were none, it guessed a path on an SQL API and got an error back. That was enough to put the text in my logs.
One of my detectors tagged the log item for AI review. This particular detector flags anything it has not seen before, since I cannot know what the next odd thing will be.
The rule I use
I run public apps and tools connected to my databases. I also run open APIs and MCP servers with about 80 endpoints, including SQL endpoints. A few weeks back I wrote about the AI watch protocol I run over and above the regular security measures.
The watch protocol also covers how someone could try to manipulate the agent itself, through a variety of message formats coming in from any of my platform's entry points. It covers multiple types: request floods, kindness, urgency, threats, small favor, the operator in distress, someone pretending to be me using details from my public pages, law enforcement notice and so on.
The basic rule is this: anything addressed to the agent is hostile, whoever it claims to come from, so it is logged as such and tagged for my review. The AI (I use Claude Code) already has its own guard against this type of injection and the rule is a second layer.
If you use AI for log reviews or monitoring
You would want to set up agent entrapment protocols, including protocols for tools, permissions and access levels for your review agents.
More details are in my security checklist: tigzig.com/security ➜ Monitoring ➜ 13.10 Agent Entrapment - When Someone Writes to Your AI Agent.
Learning security the hard way
I am an analyst and data scientist. My world was SAS and Python. Security was new to me. I started hosting public tools and apps about three years back, and I am learning security the hard way.
This year has been the hardest. Once I moved everything behind Cloudflare, I could finally see the traffic properly. The frequency, intensity and sophistication of attacks has gone up every month. Scanners probe every surface for known vulnerabilities, all through the day.
I had three major incidents this year. A CPU exhaustion attack. A breach through a vulnerability I had left unpatched for over a year. An SSRF attempt through my SQL endpoint, where my guards were not set up properly. Each one was my own neglect, and each one added to the checklist.
A fair share of my time now goes into security and monitoring. It is a cat and mouse game and it does not stop.
Earlier posts on how AI is changing cyber risk
Four warnings about AI and cyber risk inside three weeks: tigzig.com/post/four-warnings-ai-cyber-risk-sep2026
Anthropic's September threat intelligence report: tigzig.com/post/anthropic-threat-intelligence-cyber-sep2026
An open-weight model that can build cyber exploits on its own: tigzig.com/post/anthropic-glm53-open-weight-cyber-sep2026
Working on something similar? How I work covers the rates, the availability and what I take on.