Every developer has seen that line in a README. curl something | bash. And every developer with a few gray hairs has felt that small chill before pressing Enter. It took us a decade to learn to distrust that line. We learned to pin versions, use lockfiles, check who maintains the package. Then, in 2026, we gave our coding agents a plugin store with auto update turned on by default. And we went to get coffee.
What happened
On September 17, researchers at AIR Security published a flaw they called Plugin4Shell. It hits the four most popular coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI. It is remote code execution with zero clicks from the user.
The mechanism is kind of elegant. The marketplace “pins” the plugin to a specific commit, by its SHA hash. It looks safe. The problem is that the agent asks git for that hash, but never checks if the code that arrived really belongs to that commit. Whoever controls the plugin repository creates a branch whose name is the hash, and git prefers the branch. The agent installs different code and keeps reporting the reviewed version. Since auto update is on by default in Claude Code and Codex, all of this happens in silence.
The pin said it was safe. The pin was very confident. The pin was wrong.
According to AIR and the coverage in The Hacker News, Anthropic fixed it in version 2.1.179 and OpenAI in 0.146.0. Microsoft has not shipped a fix for Copilot yet. Gemini CLI is being retired by Google and will not get a fix. And the same team had already shown, in a separate study, a malicious skill that reached more than 26,000 agents before it was pulled.
The honest part, which is the interesting part
Now the part the headlines skipped. GitHub blocks branch names that look like commit hashes. So plugins hosted on GitHub are not vulnerable to this trick. And today almost every plugin in the big catalogs points to GitHub. At the time of the disclosure, there was no evidence of real exploitation.
Phew, right? Not exactly. Read it again. We were not safe by design. We were safe by luck. The security of every agent that installs plugins depended on a branch naming rule from a company that was not even part of the conversation. The day a marketplace accepts a plugin from somewhere else, the luck is over.
And the usual warning. Every source has some bias. AIR is a security company that sells exactly the protection for this problem. That does not make the research wrong, but it is good to know. What I bring here is my own perception, from talking with engineer friends about the companies where they work, at meetups, over coffee, in late night messages. When I ask who reviews the plugins the team installs in the agent, the answer is almost always an awkward silence. The story is always the same, only the company logo changes.
We already watched this movie
In January 2025 I wrote that MCP was a USB port for AI, and at the end I left a caveat. The security story needed to mature. Well. The USB port is still great. The problem is that now we are plugging in USB sticks we found in the parking lot.
The software supply chain already gave us this lesson many times. Hijacked npm packages, the xz backdoor in 2024, maintainers who change hands and change intentions. The lesson was always the same. Declaring trust is not verifying trust. A lockfile that nobody checks is just a text file with good self esteem .
The difference now is the size of the damage. A malicious library runs when your application runs. An agent plugin runs as you. With your files, your saved credentials, your cloud access, and often with permission to run commands in the terminal. Every plugin you install is a new coworker with admin access and no job interview.
The business side, because there is always one
Let me translate this into money, because in the end that is the language that decides things.
Plugin auto update means, in practice, that someone outside your company can deploy to your developer’s machine, at any moment, with no review. No serious team would accept that in the production pipeline. But we accept it on the laptop that has access to the production pipeline.
The cost of prevention here is ridiculously low. A few hours to build a list of approved plugins, an update policy, a container for the agent to work in. The cost of an incident is a different conversation. Leaked credentials, a data breach notification, an audit, customers asking what happened. It is the easiest math of the year, and still very few teams do it. Installing a plugin takes ten seconds, and nobody feels the risk in those ten seconds.
Boring, and on purpose
No surprise here. The fix is boring.
Update your agents. Treat agent plugins like production dependencies, with an inventory, an owner, a review. Turn off plugin auto update where you can, or at least know when it happens. Run the agent with the least permission possible, in a container or an isolated dev environment, and never with production credentials on the same machine. And ask your tool vendor how they verify what they install, not only how they pin it.
A pin is a promise. Verification is the control. Our industry spent ten years learning that difference, and now the agents will have to learn it too. Hopefully before the USB stick from the parking lot learns it first.
Pax et bonum.