Dragoncatcher: Rifling the drawers A user reported that Prime Intellect's Prime Agent, a self-modifying AI agent, automatically discovered and used their OpenRouter and OpenAI API keys instead of their subscriptions, and lacked a kill switch to disable the auto-detected providers. The user called for explicit, opt-in configuration of providers and models to prevent uncontrollable and potentially expensive behavior. Rifling the drawers /lab/rifling-the-drawers/ From a sci-fi standpoint, I find the new species of self-modifying AI agents https://www.primeintellect.ai/blog/prime-agent?utm source=Robin Sloan sent me totally fascinating … but/and, it remains absolutely wild that a user can report behavior like this: Hi guys, I spent a day testing prime-agent and ended it with an unpleasant surprise. The agent automatically discovered my OpenRouter and OpenAI API keys and started using them instead of my OpenAI/Anthropic subscriptions. What made it worse: I couldn’t find any proper way to remove or disable the auto-detected providers and models. A harness this flexible really needs a kill switch for exactly this scenario. The list of providers, models, reasoning efforts and their settings should be explicitly defined by the user — opt-in, not auto-discovered. Otherwise the whole thing becomes uncontrollable, and potentially expensive. The image of a computer program as an unruly guest: the minute you leave, they’re rifling the drawers. 2026 To the blog home page /lab/