AI Coding-Agent Isolation, Logging, and Verification Gaps
Heapjack let hostile repository content reach unsandboxed execution even in read-only mode, while Overpatch used symlinked shell configuration to cross the workspace-write boundary. Git branch-versus-commit attacks, Plugin4Shell's post-download mutation scenario, and OpenCode's persistent transcript exposure of write-tool secrets extend the pattern across multiple agents; the roughly 48,000-file Claude Code deletion report remains lower-confidence because its Reddit source was deleted.
Sources (2)
Updated Sep 29, 2026