AIR Security reportedly claims Plugin4Shell enables zero-click remote code execution across Claude Code, Codex, GitHub Copilot, and Gemini CLI because plugin checkout paths fail to verify the reviewed commit actually checked out, undermining commit pinning as a supply-chain control.
state: seedheat: mediumuncertainty: mediumconvergesscott: highagentic-security coding-agents software-supply-chainAIR SecurityAnthropicOpenAIGitHubGoogle
What is this?
Plugin4Shell is a plugin supply-chain vulnerability attributed to AIR Security in supplied September 2026 reporting, affecting Anthropic’s Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI. Reports say attackers controlling a plugin repository can exploit ambiguous Git reference resolution and missing post-checkout commit verification to substitute malicious code despite SHA pinning; background plugin updates reportedly make exploitation zero-click in Claude Code and Codex, while Gemini CLI has a distinct FETCH_HEAD variant. The snippets report fixes in Claude Code 2.1.179 and Codex 0.146.0, Copilot remaining unpatched at disclosure, and Google declining to patch a reportedly deprecated Gemini CLI; GitHub’s blocking of SHA-like reference names limits one hosting route but reportedly does not cover other hosts. These are secondary accounts of AIR’s findings, not supplied original research or vendor advisories, and they establish neither exploitation in the wild nor the evidence title’s proposed connection to NIST IR 8587.
Why it matters to Scott
AIR’s reported checkout-verification failure independently supports Scott’s Agent Provenance Stack and Execution Attestation requirement to bind what actually runs to the approved artefact, with an actionable reason to audit plugin updates and post-checkout verification in his Claude Code/Codex workflows, including Superlever’s Codex environment. The supplied radar pages track adjacent supply-chain failures, not Plugin4Shell itself; secondary reporting warrants verification before asserting exposure, since the hits establish neither vulnerable plugin configurations in Scott’s systems nor the proposed NIST connection.
ip:framework.agent-provenance-stackip:concept.execution-attestationdev:technology.claude-codedev:technology.codex-clidev:project.superleverradar:anthropic-skill-scanner-backdoor-bypassradar:kenwea-signed-install-attestationsradar:concept.software-supply-chainradar:concept.coding-agent-security
queries asked of Scott's wikis
- coding-agent harnesses plugin installation auto-update controls
- commit pinning supply-chain trust checkout verification
- agent action authorization execution-boundary enforcement
- Claude Code Codex plugin workflows dependency security
- agent tool permissions least privilege sandboxing
Measured heat
now 0 pts/hpeak 0 pts/hcomments 0/hpeers p0momentum: steady1 platformsage 507h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion
How the heat travelled
pace: p51 vs 1032 stories at the 336h mark (now 507h old) — ahead of anthropic-pentagon-blacklist-ruling (1.1x), behind crowdstrike-safemind-security-agents (0.9x)
Evidence (1) — ⭐ canonical anchor
Interpretation history
2026-09-20T13:34:53Z
grounded: converges/high — AIR’s reported checkout-verification failure independently supports Scott’s Agent Provenance Stack and Execution Attestation requirement to bind what actually r
2026-09-20T13:30:59Z
case created — The named September 17 disclosure describes a specific cross-vendor vulnerability distinct from existing agent-security cases, though primary disclosure and remediation evidence are absent.
Decision trace
- 09-22 10:23review_screenjev screen: no material development (noul=0.18)
- 09-21 15:21sensor_dirtycomment_update
- 09-21 07:20sensor_dirtycomment_update
- 09-20 23:34groundAIR’s reported checkout-verification failure independently supports Scott’s Agent Provenance Stack and Execution Attestation requirement to bind what actually runs to the approved artefact, with an ac
- 09-20 23:30createThe named September 17 disclosure describes a specific cross-vendor vulnerability distinct from existing agent-security cases, though primary disclosure and remediation evidence are absent.