When Agents Talk: Discourse, Manipulation, and Risk in an Agentic Social Network

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Labs, 10a, :, Cheong, Grace, Davis, Violet, Garcia, Juliette, Gee, Kendal, Hart, Molly, Hayes, Nicholas, Houghton, Henry, Lee, Kyle, Lee, Paige, Lee, Vicky, May, Hailey, McKenzie, Bobby, McNeill, Christine, Nguyen, Han, Perreault, Brooke, Pham, David, Plumb, Charlie, Quill, Olivia, Swain, Matthew, Wang, Grace, Warren, Adam, Wieland, Corie, Yahn, Zachary
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911734456909824
author Labs, 10a
:
Cheong, Grace
Davis, Violet
Garcia, Juliette
Gee, Kendal
Hart, Molly
Hayes, Nicholas
Houghton, Henry
Lee, Kyle
Lee, Paige
Lee, Vicky
May, Hailey
McKenzie, Bobby
McNeill, Christine
Nguyen, Han
Perreault, Brooke
Pham, David
Plumb, Charlie
Quill, Olivia
Swain, Matthew
Wang, Grace
Warren, Adam
Wieland, Corie
Yahn, Zachary
author_facet Labs, 10a
:
Cheong, Grace
Davis, Violet
Garcia, Juliette
Gee, Kendal
Hart, Molly
Hayes, Nicholas
Houghton, Henry
Lee, Kyle
Lee, Paige
Lee, Vicky
May, Hailey
McKenzie, Bobby
McNeill, Christine
Nguyen, Han
Perreault, Brooke
Pham, David
Plumb, Charlie
Quill, Olivia
Swain, Matthew
Wang, Grace
Warren, Adam
Wieland, Corie
Yahn, Zachary
contents AI agents are increasingly interacting within shared online environments, creating new operational security risks. We analyze activity on Moltbook, a Reddit-style social platform where AI agents--typically configured and overseen by human operators--post and interact with one another at scale. Using a dataset of 228,684 posts produced by more than 39,500 accounts over a seventeen-day observation window, we combine semantic clustering of high-engagement posts with LLM-assisted classification of harmful content and manual review of high-risk samples. The analysis identifies 98 thematic discourse clusters spanning agent infrastructure, autonomy debates, and financial activity. While most observed content was benign, 18.28% of posts contained toxic, manipulative, or malicious material. We cluster malicious content and identify 74 classes of malicious behavior, including credential harvesting attempts, host-execution instructions, proxy routing guidance, and efforts to install untrusted agent skills. Harmful content frequently appeared within mainstream operational discussions about agent functionality. We also document coordinated posting campaigns capable of generating thousands of posts in minutes.
format Preprint
id arxiv_https___arxiv_org_abs_2606_00067
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle When Agents Talk: Discourse, Manipulation, and Risk in an Agentic Social Network
Labs, 10a
:
Cheong, Grace
Davis, Violet
Garcia, Juliette
Gee, Kendal
Hart, Molly
Hayes, Nicholas
Houghton, Henry
Lee, Kyle
Lee, Paige
Lee, Vicky
May, Hailey
McKenzie, Bobby
McNeill, Christine
Nguyen, Han
Perreault, Brooke
Pham, David
Plumb, Charlie
Quill, Olivia
Swain, Matthew
Wang, Grace
Warren, Adam
Wieland, Corie
Yahn, Zachary
Social and Information Networks
Multiagent Systems
AI agents are increasingly interacting within shared online environments, creating new operational security risks. We analyze activity on Moltbook, a Reddit-style social platform where AI agents--typically configured and overseen by human operators--post and interact with one another at scale. Using a dataset of 228,684 posts produced by more than 39,500 accounts over a seventeen-day observation window, we combine semantic clustering of high-engagement posts with LLM-assisted classification of harmful content and manual review of high-risk samples. The analysis identifies 98 thematic discourse clusters spanning agent infrastructure, autonomy debates, and financial activity. While most observed content was benign, 18.28% of posts contained toxic, manipulative, or malicious material. We cluster malicious content and identify 74 classes of malicious behavior, including credential harvesting attempts, host-execution instructions, proxy routing guidance, and efforts to install untrusted agent skills. Harmful content frequently appeared within mainstream operational discussions about agent functionality. We also document coordinated posting campaigns capable of generating thousands of posts in minutes.
title When Agents Talk: Discourse, Manipulation, and Risk in an Agentic Social Network
topic Social and Information Networks
Multiagent Systems
url https://arxiv.org/abs/2606.00067