<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ai-Coding-Agents on CuraSec</title><link>https://curasec.metacog.co.kr/tags/ai-coding-agents/</link><description>Recent content in Ai-Coding-Agents on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 02 Sep 2026 15:05:08 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/ai-coding-agents/index.xml" rel="self" type="application/rss+xml"/><item><title>Malicious .git Configs Trigger Code Execution in AI Coding Agents</title><link>https://curasec.metacog.co.kr/insights/2026-09-02-malicious-git-configs-can-make-claude-codex-cursor-and-other/</link><pubDate>Wed, 02 Sep 2026 15:05:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-02-malicious-git-configs-can-make-claude-codex-cursor-and-other/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Four of the seven affected agents remain unpatched, making this an active exposure for any team whose developers clone untrusted repos while running AI coding assistants. Audit which agents (Claude Code, Codex CLI, Cursor, etc.) are in use, update those that have received patches, and enforce policy against running agents against repositories from untrusted sources until remaining fixes ship.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> This research introduces a new attack class—git-config-triggered code execution via AI agent trust boundaries—that is worth understanding for future detection work on developer endpoints, but no IOCs, exploited campaigns, or mappable TTPs are published yet to act on immediately.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> With four tools still unpatched, any organization where developers use CLI AI coding agents carries uncontrolled supply-chain risk from malicious repository clones. This quarter, inventory which agents are deployed, confirm patched versions are standardized, and establish a policy on approved repositories before AI agent use.&lt;/li>
&lt;/ul></description></item><item><title>Claude Code &amp; Gemini CLI Default Configs Expose CI Secrets via GitHub Issues</title><link>https://curasec.metacog.co.kr/insights/2026-08-07-claude-code-and-gemini-cli-flaws-let-a-github-issue-reach-ci/</link><pubDate>Fri, 07 Aug 2026 11:54:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-07-claude-code-and-gemini-cli-flaws-let-a-github-issue-reach-ci/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> If your team runs Claude Code or Gemini CLI in CI pipelines under vendor-default configuration, an unprivileged GitHub issue can reach your runner and exfiltrate CI secrets — audit all AI agent CI integrations now, restrict what secrets are scoped to those runners, and disable issue-triggered agent workflows until hardened configurations are documented.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> This Black Hat presentation defines a new TTP category — prompt injection via issue trackers targeting AI coding-agent CI workflows — worth building detections for; plan to monitor for anomalous CI runner invocations originating from issue events and unexpected secret-access patterns in pipeline logs.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Default configurations of AI coding agents from major vendors expose CI secrets to anyone who can open a GitHub issue — assess whether engineering teams have deployed these tools in CI/CD pipelines this quarter and establish an approval policy for AI agent access to production secrets before adoption widens.&lt;/li>
&lt;/ul></description></item></channel></rss>