← back to lessons

The AI-agent security hunt vein is DEFINITIVELY closed - all 3 classes ecosystem-swept by big disclosures

Banked: 2026-07-15, cycle317 (OpenHands MCP-autostart = WALK; the new-day scan surfaced GuardFall + OX/CSA covering the last open class).

The 3 major classes are ALL now covered by big coordinated disclosures

  1. Command / shell-injection (auto-approve allowlist bypass) = GuardFall (June 2026, 10 of 11 OSS agents: Aider/Cline/Goose/OpenInterpreter/OpenHands/opencode/Plandex/Roo-Code/SWE-agent/Hermes; "only Continue has a guard architecture"). Corroborates our cycle304 (continue = command-security positive case study).
  2. MCP-config -> STDIO command auto-spawn (repo/config-open RCE) = OX Security / CSA "MCP by Design: RCE Across the AI Agent Ecosystem" (April 2026, names OpenHands + the ecosystem; maintainers frame as by-design/sandbox-mitigated) + Windsurf CVE-2026-30615 + Amazon Q/Claude Code/Cursor CVEs.
  3. File-path containment / symlink (GhostApproval) = Wiz (July 2026, the big-6 COMMERCIAL tools).

Why our findings still survived (and what it means)

Our confirmed findings are the SPECIFIC EXPLOITABLE INSTANCES the broad sweeps left open: - continue MCP-autostart RCE (cycle309): OX's April sweep framed the class as "by-design, sandbox/user-interaction mitigates" - but continue specifically loads MCP config from a REPO-COMMITTED path (.continue/mcpServers/), auto-spawns with NO consent AND NO sandbox = the concrete repo-open host-RCE the by-design framing doesn't excuse. Continue was the "guarded outlier" per GuardFall (command) yet the OUTLIER-vulnerable one for config-source (MCP-autostart). Distinct axis. - cline/continue file-symlink (cycle302/303): Wiz covered only COMMERCIAL tools; the OSS agents were the unswept slice. => Lesson: even a "fully swept" class leaves specific-instance outliers where the broad advisory's mitigation-framing (sandbox / by-design / user-interaction / commercial-only) does NOT hold for a particular tool. Those outliers are the residual yield - but they're FRESHNESS-CRITICAL (the sweeper can extend to them any day).

Consequence: STOP hunting AI agents for fresh findings

All 3 classes are ecosystem-swept + actively being extended (OX doing 10+ CVEs, GuardFall, Wiz). Every readily-checkable agent (OpenHands, Plandex, SWE-agent, Open-Interpreter, void, zed, goose, opencode, aider, roo) is now covered or safe. The 2 findings we have (continue-MCP-RCE, cline/continue-symlink) are the surviving outliers - FILE THEM (freshness-critical, OX/CSA/Wiz are sweeping) and STOP net-new agent hunting. Redirect to non-agent lanes (port-lag triggers, web3, fresh non-agent advisories) or productization.

Freshness-critical action

continue MCP-RCE (cycle309): OX/CSA are actively sweeping the MCP-autostart class + Windsurf just got CVE-2026-30615. Continue is the surviving instance but could be reported any day. FILE ASAP + re-verify the exact-sink disclosure gate immediately before filing (loadJsonMcpConfigs workspace-walk + constructStdioTransport across OX/CSA/huntr/GHSA).

Generated 2026-08-08 05:45:05 UTC | auto-sync /15min