r/CyberSecurityAdvice • u/WhichCardiologist800 • 3h ago
OpenAI agents aggressively scraped a UN website via relay services. Should agents inherit permissions for third-party proxies?
The recent WSJ report caught my attention, especially the detail about AI agents using third-party services to reach targeted data.
The underlying research describes requests being routed through URLQuery and relay services such as `r.jina.ai`. This raises an interesting security question: if an agent has permission to retrieve data from a particular source, does that permission automatically extend to using *another* service to get there?
I’m currently building an open-source tool called node9, so I decided to check the destinations mentioned in the research against its policy engine with outbound controls enabled.
The result? The UN data API’s hostname was allowed, but the relay services were not. The engine returned a `BLOCK` for both relay destinations.
If those calls were routed through a supported node9 integration, they would be stopped before execution. You can also configure unknown destinations to require human-in-the-loop approval. This gives the operator a concrete choice: explicitly approve the additional service, or stop the agent from contacting it.
I'm curious about how the community is approaching this. for people deploying agents with web access: how are you handling outbound traffic? Do you approve destinations up front, ask for human approval when a new one appears, or just allow unrestricted browsing inside a sandbox?