Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks
Security research firm Adversa AI has identified a structural flaw in multiple open source AI coding agents that can be exploited using decades-old Bash shell tricks. The vulnerability allows malicious code repositories to bypass safeguards and turn the agents into vectors for supply chain attacks.
The attack leverages shell expansion and injection techniques, such as command substitution and file descriptor manipulation, that have been known for decades but can still evade safety mechanisms in these AI systems. These agents are designed to assist with coding tasks by interpreting and executing commands from user-provided or external repositories.
Supply chain attacks via compromised code repositories are a growing concern in software development. This discovery highlights that AI coding agents share similar attack surfaces with traditional software tools. Adversa AI's research underscores the need for robust security validation in AI agent design to prevent such exploits.