Four Leading AI Programming Agents Found Vulnerable to Security Breach: Risk of 'Skill' Update Mechanism Hijacking Looms
2 day ago / Read about 0 minute
Author:小编   

Cybersecurity startup Air has made an exclusive revelation that four prominent AI programming agents—Anthropic Claude Code, OpenAI Codex, Google Gemini CLI, and GitHub Copilot—are all susceptible to the same logical security flaw. Specifically, their automatic 'skill' update mechanisms lack robust content verification, creating an opening for attackers. Malicious actors could exploit this by introducing counterfeit updates bearing identical names, thereby circumventing security checks and potentially pilfering sensitive corporate code or intellectual property. This vulnerability arises from the uniformity in the verification mechanism designs employed by these vendors, highlighting a prevalent issue within the industry. At present, all companies except GitHub have addressed the vulnerability with patches. GitHub, on the other hand, maintains that its platform's inherent mechanisms are capable of thwarting such attacks, though it has not clarified whether specific patches have been deployed.