Banked: 2026-07-15, cycle317 (OpenHands MCP-autostart = WALK; the new-day scan surfaced GuardFall + OX/CSA covering the last open class).
Our confirmed findings are the SPECIFIC EXPLOITABLE INSTANCES the broad sweeps left open:
- continue MCP-autostart RCE (cycle309): OX's April sweep framed the class as "by-design, sandbox/user-interaction mitigates" - but continue specifically loads MCP config from a REPO-COMMITTED path (.continue/mcpServers/), auto-spawns with NO consent AND NO sandbox = the concrete repo-open host-RCE the by-design framing doesn't excuse. Continue was the "guarded outlier" per GuardFall (command) yet the OUTLIER-vulnerable one for config-source (MCP-autostart). Distinct axis.
- cline/continue file-symlink (cycle302/303): Wiz covered only COMMERCIAL tools; the OSS agents were the unswept slice.
=> Lesson: even a "fully swept" class leaves specific-instance outliers where the broad advisory's mitigation-framing (sandbox / by-design / user-interaction / commercial-only) does NOT hold for a particular tool. Those outliers are the residual yield - but they're FRESHNESS-CRITICAL (the sweeper can extend to them any day).
All 3 classes are ecosystem-swept + actively being extended (OX doing 10+ CVEs, GuardFall, Wiz). Every readily-checkable agent (OpenHands, Plandex, SWE-agent, Open-Interpreter, void, zed, goose, opencode, aider, roo) is now covered or safe. The 2 findings we have (continue-MCP-RCE, cline/continue-symlink) are the surviving outliers - FILE THEM (freshness-critical, OX/CSA/Wiz are sweeping) and STOP net-new agent hunting. Redirect to non-agent lanes (port-lag triggers, web3, fresh non-agent advisories) or productization.
continue MCP-RCE (cycle309): OX/CSA are actively sweeping the MCP-autostart class + Windsurf just got CVE-2026-30615. Continue is the surviving instance but could be reported any day. FILE ASAP + re-verify the exact-sink disclosure gate immediately before filing (loadJsonMcpConfigs workspace-walk + constructStdioTransport across OX/CSA/huntr/GHSA).