← Founder Notes
Archive

The four big coding agents now share a supply chain hole that makes reviewed plugins meaningless.…

Yethikrishna ROriginal on Threads

the four big coding agents now share a supply chain hole that makes reviewed plugins meaningless. plugin4shell, disclosed sept 18, gives zero-click remote code execution across codex, claude code, gemini cli and copilot because a git sha hash is the only integrity check, and anyone with write access can swap the code behind it.

the safe default is no third-party plugins until the trust model changes.

Context

Air Security's post of 17 September 2026 describes a plugin SHA-pinning bypass: the agent checks out the commit the marketplace pinned but never verifies it landed there, so an attacker who controls a plugin's repository can make the checkout resolve to malicious code. Zero-click depends on auto-update, the default in Claude Code and Codex. Claude Code, Codex and Copilot share one variant, where a branch named like the pinned hash is preferred over the commit, and Gemini CLI has a different variant. Air says Anthropic patched Claude Code in 2.1.179.

How it compares

This is the author's take on a vendor disclosure. Air also sells security products. It requires a marketplace plugin the user already installed whose repository the attacker controls, so it is not a blanket flaw on every machine running these agents. Air's described check is not that a git hash is the only integrity check, but that the checkout is never verified after the fact. Other vendors' fix versions and CVE identifiers were not located, and no exploitation in the wild was read. Sources differ on disclosure, 17 September on Air's blog and 18 September in a Cloud Security Alliance note seen as a snippet. Reviewed plugins being meaningless and the advice of no third-party plugins are the author's opinion and advice.

Related work

Watch next

  • Per-vendor advisories, fixed versions and CVE identifiers.

Sources

  1. Plugin4Shell (Air Security, 17 Sep 2026)air.security

Provenance

The note above is reproduced unedited from the original post, first published on Threads on 20 September 2026 at 00:21 IST. Sources are the papers and datasets the note draws on.

View the original post
Embed this note
<iframe src="https://founder.myndlabs.tech/notes/embed/the-four-big-coding-agents-now-share-a-DdesgnYkWji" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="The four big coding agents now share a supply chain hole that makes reviewed plugins meaningless.…"></iframe>

More notes