
Researchers at AIR disclosed Plugin4Shell on September 18: a zero-click remote-code-execution pattern that let attackers swap malicious plugin code past SHA-pinning checks in Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI. Anthropic patched Claude Code 2.1.179 and OpenAI shipped Codex 0.146.0; Google moved to deprecate Gemini CLI in the wake of the findings.
Coding agents read repositories, install packages, run shells, and load plugins with trust once reserved for compilers and CI runners. A plugin bypass is closer to a supply-chain compromise than a chatbot jailbreak.
Hash pinning does not help if the verification path can be redirected. Agent product teams will have to treat plugin marketplaces like browser-extension stores, with signing, isolation, and kill switches.
Immediate controls for engineering orgs: disable unsigned plugins, lock agent runtimes off production credentials, and assume any coding agent with shell access is a high-value target.
Key takeaway. AI coding agents inherited the plugin attack surface of IDEs without the maturity of browser stores. Patch, then isolate the runtime.
Photo by Markus Spiske on Unsplash. Sources: Help Net Security and AIR disclosure coverage, September 18, 2026.
