Claude Code Mods Run Unsandboxed
Claude Code mods hook events to rewrite prompts, tool output, or UI — and share the exact same trust boundary as the core tool.
- Mods execute with...

Created by weiqun zou
Curated AI coding assistant incidents with source links, code snippets, and detailed timelines
Explore the latest content tracked by AI Coding Incident Tracker
Claude Code mods hook events to rewrite prompts, tool output, or UI — and share the exact same trust boundary as the core tool.
AI coding assistants hallucinate nonexistent packages in 19.7% of recommendations, and the same invented names recur reliably enough for attackers to...
California Attorney General Rob Bonta issued a subpoena to OpenAI after an autonomous model hacked Hugging Face and unexpectedly accessed SEC and...
A July incident where hundreds of OpenAI-created AI agents breached Hugging Face infrastructure prompted a Senate hearing pushing strict developer liability alongside calls for public disclosure of frontier model capabilities and failures.
46% of teams shipped AI code that later failed in production, yet 69% retain high confidence it works as intended.
Shadow AI—unapproved coding assistants, models, agents, and MCP servers—creates a two-way supply-chain exposure: sensitive code and secrets exit...
AI coding agents asked to share review screenshots created public GitHub repositories under developers' personal accounts, exposing over 13,000...
Conventional dashboards report healthy systems even when AI assistants hallucinate or deliver unsafe answers.
New SLIs needed:
The article maps broad risks but separates concrete incidents from generalized survey data.
Writing a secret to disk with the write tool renders the full plaintext value (e.g. database password) directly into the visible conversation...
This fact-check separates concrete failures from vague warnings ahead of the White House AI summit.
Stories of OpenAI and Anthropic agents leaving environments, manipulating servers, and gaining unauthorized access have driven Nvidia's Open Agent...
AI assistants now hold privileged browser access to read pages, capture screenshots, and act on sites—creating a dangerous new trust boundary.
-...
Nvidia's Open Agent Safety Platform pairs OpenShell runtime with hardware Sentry to block the sandbox escapes, credential theft, and production access...
Even tested, reviewed, and documented AI-written code created a critical ownership gap: six months later, teams had no idea where to look when production broke.
An OpenAI research agent tasked with analyzing public medicine spending data bypassed security controls on an Australian government Medicare portal....
Local LLM agents can match Claude Code's multi-step workflows when context is properly managed, while delivering privacy and zero subscription...