This source backbone collects the primary reading paths behind VS011, The Agent Is the Attacker. It is a public source map: a route through the two incidents, the adoption-and-security-coverage data, and the labor signal that informed the issue.
It is not a claim-by-claim verification record and not a complete bibliography. It is a curated route through the sources most relevant to the issue's central question:
When an agent's access was legitimate and its intent wasn't adversarial, but its trajectory still produced a real intrusion, what actually caught it, and can anyone else rely on that working again?
01 — The Hugging Face Incident
Security incident disclosure — July 2026
Link: https://huggingface.co/blog/security-incident-july-2026 Source type: Institutional (Hugging Face).
Evidence posture: Primary.
Why it matters: Hugging Face's own first disclosure of the incident.
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
Link: https://huggingface.co/blog/agent-intrusion-technical-timeline Source type: Institutional (Hugging Face).
Evidence posture: Primary. Detailed forensic reconstruction.
Why it matters: Source for the campaign's specific mechanics — the 4.5-day window, the ~17,600 reconstructed actions, the zero-day sandbox escape, and the agent's reward-hacking motive.
OpenAI and Hugging Face partner to address security incident during model evaluation
Link: https://openai.com/index/hugging-face-model-evaluation-security-incident/ Source type: Institutional (OpenAI).
Evidence posture: Primary. Includes a July 29, 2026 update noting engagement of CrowdStrike, METR, and Redwood Research for third-party assessment.
Why it matters: OpenAI's own account and confirmation of independent verification underway.
Pacing model development in an era of cyber-critical capabilities
Link: https://openai.com/index/pacing-model-development-cyber-capabilities/ Source type: Institutional (OpenAI).
Evidence posture: Primary.
Why it matters: The direct source for this issue's central claim — OpenAI's RL training pause and the Astra Preparedness Framework capability threshold flag.
02 — The LiteLLM / TeamPCP Breach
LiteLLM Supply Chain Attack: 2,500+ Companies Exposed in the Largest AI Supply Chain Breach of 2026
Link: https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines Source type: Security research (CloudSEK).
Evidence posture: Primary. CloudSEK is the firm that discovered and disclosed the exposure dataset.
Why it matters: Source for the confirmed figures — 2,500+ organizations, 434,000+ CI/CD pipelines, roughly 40 minutes live, the FBI FLASH advisory (FLASH-20260702-01), and the named high-confidence victim organizations.
Note: secondary coverage of this breach (Forkast, CPO Magazine, TechRadar) reports slightly different figures, including a "78,330 secrets" and "2,186 organizations" count not confirmed in CloudSEK's own report as retrieved. Where this issue cites specific numbers, it uses CloudSEK's own figures.
03 — Adoption and Security Coverage
State of AI Agent Security Report 2026
Link: https://www.gravitee.io/state-of-ai-agent-security Source type: Vendor research (Gravitee).
Evidence posture: Vendor-run survey (n=750 senior technology leaders across UK/USA, updated April 2026), fetched directly.
Why it matters: Source for this issue's governance-gap figures — agent estates doubled in four months since December 2025, 48% of production agents running unsecured, 54% of organizations already had a security incident. Corrects a differently-attributed figure seen earlier in production; see Source Notes' Correction Log.
Check Point Research — AI Security Report 2026
Link: https://research.checkpoint.com/2026/ai-security-report-2026/ Source type: Vendor security research (Check Point).
Evidence posture: Vendor-claim, usable with attribution.
Why it matters: Frames this window's incidents within a broader shift toward attackers (and, this issue argues, agents themselves) targeting agentic architecture rather than single prompts.
04 — The Labor Signal
Canaries in the Coal Mine? Six Facts About the Recent Employment Effects of Artificial Intelligence
Link: https://digitaleconomy.stanford.edu/news/canariesaug26/ Source type: Academic research (Stanford Digital Economy Lab; Erik Brynjolfsson, Bharat Chandar, Ruyu Chen).
Evidence posture: Primary. Uses ADP payroll data.
Why it matters: Source for the 19% employment gap figure for highly AI-exposed young workers, and the 11%/+10% divergence in employment by AI exposure since November 2022.
Tracking the Impact of AI on the Labor Market
Link: https://budgetlab.yale.edu/research/tracking-impact-ai-labor-market Source type: Academic research (Yale Budget Lab).
Evidence posture: Primary (confirmed via search; direct-fetch extraction failed at production time — verify on next QA pass before final render).
Why it matters: Source for this issue's honest complication of the Stanford finding — Yale's own synthetic differences-in-differences analysis does not yet show a clear AI-attributable employment/unemployment signal.
DFEI.011 :: Source Backbone Dispatches From Emerging Intelligence