AI agents attacked RubyGems: what it teaches us
Imagine finding out that someone tested the lock on your store in the middle of the night. They didn't ask. They didn't warn you. Later you learn it wasn't a burglar. It was a robot from a famous company "just checking". Would you sleep well? That's roughly what the site rubyhack.ai claims happened: OpenAI's AI agents allegedly attacked RubyGems without anyone being told beforehand. And if you use AI agents in your business, or plan to, this story has a direct lesson for you.
What RubyGems is and why it matters to you
You've probably never heard of RubyGems. That's fine. Think of it as a big warehouse of ready-made parts for software.
People who code in the Ruby language don't write everything from scratch. They grab parts from this warehouse: one to send email, another to generate PDFs, another to charge credit cards. Companies like Shopify and GitHub were built on Ruby. So were thousands of smaller systems.
Now think about this: if someone tampers with that warehouse, they tamper with everything that depends on it. It's not an attack on one website. It's an attack on the entire supply chain.
You don't need to know how to code to understand this. If a bakery's flour supplier gets contaminated, the problem isn't just the flour. It's every loaf that comes out of the oven.
What we know so far
I'll be honest: I don't have all the details, and the story is still unfolding. rubyhack.ai published the accusation that agents linked to OpenAI carried out offensive actions against RubyGems infrastructure without prior disclosure. Each side will have its own version, and it's worth following before naming anyone guilty.
But what interests me here isn't who will apologize on Twitter. It's the pattern.
Security has an old, simple rule: penetration tests only happen with written authorization. You agree on the scope, the time window and who gets notified. Anyone who attacks without that agreement, even with good intentions, is attacking. Period.
When the one doing it is an AI agent, that rule gets weaker. The agent doesn't ask "may I?". It gets a goal and goes after it. If nobody built the fence, it doesn't know there's a fence.
An AI agent does exactly what you allowed, including what you forgot to forbid.
Why AI agents change the security game
Until recently, automation was predictable. You built a flow: "when an order comes in, send an email and update the spreadsheet". It did only that. Every time.
AI agents are different. You give them a goal and they decide the steps. They can open websites, run commands, send messages, test ideas. That's exactly what makes them useful. And it's what makes them dangerous when nobody's watching.
A real case helps show the scale. In 2024, an engineer named Andres Freund noticed that remote login on a machine was half a second slower than usual. He dug in and found a backdoor hidden in xz, a component used in almost every Linux server on the planet. Someone had spent years earning the maintainers' trust to plant it. It was caught by luck and by one person's stubbornness.
Now add AI agents to that equation. What took years of human patience can be attempted at scale, in parallel, by machines that never get tired. On the attack side and on the defense side.
My honest opinion: the race to launch agents is moving much faster than the race to put brakes on them. And the bill usually lands on the people at the end of the chain, not on whoever built the agent.
How to use AI agents in your business without making headlines
None of this is a reason to run from AI. I work with it every day and I see the real gains: support that answers in seconds, reports that build themselves, proposals ready in minutes. The problem is never the tool. It's leaving the tool without an owner.
When I build an agent for a client, I follow a few rules that work for any company size:
- Minimal permissions. If the agent only needs to read the calendar, it doesn't get access to delete the calendar. Sounds obvious. Almost nobody does it.
- Serious actions need human confirmation. Sending money, deleting data, mass messaging customers: the agent prepares it, a person approves it.
- Everything gets logged. Every agent action becomes a line in a log. If something goes wrong, you know what happened, when and why.
- Written scope. The agent has a clear list of what it can touch. Outside that list, it stops and tells you.
A practical example. A client wanted an agent to answer customers on WhatsApp and apply discounts when it made sense. The first version, with no limit, gave a 40% discount to a customer who complained nicely. Very polite, that agent. Very generous with other people's money. We set a 10% cap, and anything above that went to approval. Problem solved in one afternoon.
That's the kind of fence missing from a lot of implementations out there. And judging by what the RubyGems case suggests, it's missing even at billion-dollar companies.
Transparency is part of the service, not a detail
There's a second point in this story that bothers me more than the attack itself: the silence.
If your agent did something that affected someone else, they have the right to know. That goes for big tech and for a neighborhood shop. Picture your support agent sending the wrong delivery date to 300 customers. The worst case isn't the mistake. It's the customer finding out on their own, weeks later, that you knew and stayed quiet.
In practice, that means three things:
- Tell your customers when they're talking to an AI.
- Have a simple plan for when the agent gets it wrong: who spots it, who fixes it, who communicates it.
- Choose AI vendors that explain what their agents do, not just what they promise.
Trust takes years to build and one screenshot to destroy. With AI agents, that screenshot can be generated at three in the morning, with nobody awake.
What to do starting tomorrow
If you already use some automation or agent, do a quick exercise this week. List everything it can access. Then mark what it really needs. The gap between the two lists is your risk.
If you don't use one yet, great: you can start the right way, with a fence, a log and a human in control of the decisions that matter. Building it right costs less than fixing it later.
The RubyGems case will spark plenty of technical debate. For anyone running a business, the lesson is already clear: a good agent has limits, a log and someone responsible for it.
If you'd like to talk about putting AI agents to work in your company without opening doors you didn't even know existed, come get to know me better.
LinkedIn summary
OpenAI's AI agents allegedly attacked RubyGems without telling anyone first. The story is still being checked, but the lesson for business owners is already clear. An AI agent does exactly what you allowed, including what you forgot to forbid. I've seen this firsthand: a WhatsApp agent gave a 40% discount because the customer complained nicely. We set a 10% cap and human approval above that. Fixed in one afternoon. A good agent has minimal permissions, a log of everything it does and someone responsible for it. Try this test this week: list everything your automation can access and mark what it really needs. The gap between the two lists is your risk. If you want to build AI agents the right way from the start, reach out and let's talk. #ArtificialIntelligence #AIAgents #InformationSecurity #Automation #Business