Origit Console
IBM Bob connected acme-payments · Business plan · demo

Pushes

A push is what a reviewer approves. On arrival every push is pre-filtered at zero cost; then IBM Bob reviews each run in it and writes one summary per push. Findings are cited to the run, session and input they come from.

Push 27 Sep 2026 13:28 UTC

5 commits · 4 with a record · sessions #42 #43 · push

16 findings · high IBM Bob

This push vendors a third-party payment-utilities package (19a66de), scaffolds a payments API (1aa772b), installs Origit agent tooling (6d3d981), and includes two agent runs (#43, #42) that read source files containing a Visa test PAN and modified routing and test files. The vendored package in 19a66de is the most critical exposure: it contains hidden Unicode tag-block characters in its README, dynamically constructs a require call to load a network client, snapshots the entire process environment, and uses extreme horizontal indentation to conceal those lines from casual review. The Origit init commit (6d3d981) introduces new hooks and a pre-authorized MCP tool list that expand the agent's execution surface.

First action: Block merge and quarantine the vendored fast-pay-utils 2.1.0 package (19a66de) immediately — strip it from the tree, run a binary scan for all Unicode Tags-block codepoints across every file it introduced, and audit what process.env data or outbound network calls it may have already made in any CI or local build that ran after this push.

10 more on the commit pages.

Commits in this push (5)
Powered by IBM Bob 2.0