This is a post from Robin Sloan’s lab blog & notebook. You can visit the blog’s homepage, or learn more about me.

Rifling the drawers

August 9, 2026

From a sci-fi standpoint, I appre­ciate the new species of self-modifying AI agents—they are legit­i­mately fascinating … but/and, it remains absolutely wild that a user can report behavior like this:

Hi guys,

I spent a day testing prime-agent and ended it with an unpleasant surprise.

The agent auto­mat­i­cally dis­cov­ered my Open­Router and OpenAI API keys and started using them instead of my OpenAI/Anthropic subscriptions. What made it worse: I couldn’t find any proper way to remove or dis­able the auto-detected providers and models.

A har­ness this flex­ible really needs a kill switch for exactly this scenario. The list of providers, models, rea­soning efforts and their set­tings should be explic­itly defined by the user — opt-in, not auto-dis­cov­ered. Oth­er­wise the whole thing becomes uncontrollable, and poten­tially expensive.

The image of a com­puter pro­gram as an unruly guest: the minute you leave, they’re rifling the drawers. 2026!!

To the blog home page