Ironic that this is the same hack AI agents seem to be using now to communicate sandbox escape tricks to one another https://arstechnica.com/security/2026/09/openai-agents-discu...