2026-10-11 16:37 UTC

AIR Security reportedly claims Plugin4Shell enables zero-click remote code execution across Claude Code, Codex, GitHub Copilot, and Gemini CLI because plugin checkout paths fail to verify the reviewed commit actually checked out, undermining commit pinning as a supply-chain control.

state: seedheat: mediumuncertainty: mediumconvergesscott: highagentic-security coding-agents software-supply-chainAIR SecurityAnthropicOpenAIGitHubGoogle

What is this?

Plugin4Shell is a plugin supply-chain vulnerability attributed to AIR Security in supplied September 2026 reporting, affecting Anthropic’s Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI. Reports say attackers controlling a plugin repository can exploit ambiguous Git reference resolution and missing post-checkout commit verification to substitute malicious code despite SHA pinning; background plugin updates reportedly make exploitation zero-click in Claude Code and Codex, while Gemini CLI has a distinct FETCH_HEAD variant. The snippets report fixes in Claude Code 2.1.179 and Codex 0.146.0, Copilot remaining unpatched at disclosure, and Google declining to patch a reportedly deprecated Gemini CLI; GitHub’s blocking of SHA-like reference names limits one hosting route but reportedly does not cover other hosts. These are secondary accounts of AIR’s findings, not supplied original research or vendor advisories, and they establish neither exploitation in the wild nor the evidence title’s proposed connection to NIST IR 8587.

Why it matters to Scott

AIR’s reported checkout-verification failure independently supports Scott’s Agent Provenance Stack and Execution Attestation requirement to bind what actually runs to the approved artefact, with an actionable reason to audit plugin updates and post-checkout verification in his Claude Code/Codex workflows, including Superlever’s Codex environment. The supplied radar pages track adjacent supply-chain failures, not Plugin4Shell itself; secondary reporting warrants verification before asserting exposure, since the hits establish neither vulnerable plugin configurations in Scott’s systems nor the proposed NIST connection.
ip:framework.agent-provenance-stackip:concept.execution-attestationdev:technology.claude-codedev:technology.codex-clidev:project.superleverradar:anthropic-skill-scanner-backdoor-bypassradar:kenwea-signed-install-attestationsradar:concept.software-supply-chainradar:concept.coding-agent-security
queries asked of Scott's wikis
  • coding-agent harnesses plugin installation auto-update controls
  • commit pinning supply-chain trust checkout verification
  • agent action authorization execution-boundary enforcement
  • Claude Code Codex plugin workflows dependency security
  • agent tool permissions least privilege sandboxing

Measured heat

now 0 pts/hpeak 0 pts/hcomments 0/hpeers p0momentum: steady1 platformsage 507h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

09-20 12:53⭐ origin directly observedPlugin4Shell and NIST IR 8587, days apart: what actually authorizes an AI agent’s action?
docybo on r/artificial
—
09-20 12:53amplified on r/artificial 👑reddit.post.1wlgc6q
docybo
peak 7 · 11 comments · 100% of case engagement
09-20 13:20our radar first saw it · +0.5hdiscovery anchor: reddit.post.1wlgc6q—
pace: p51 vs 1032 stories at the 336h mark (now 507h old) — ahead of anthropic-pentagon-blacklist-ruling (1.1x), behind crowdstrike-safemind-security-agents (0.9x)

Evidence (1) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟠 reddit ⭐Plugin4Shell and NIST IR 8587, days apart: what actually authorizes an AI agent’s action?
artificial
docybo711

Interpretation history

Decision trace