October AI Coding Agent Security Roundup: This Month, Attackers Barely Touched the Model — They Went After the Harness
Adversa AI's October digest collects 26 security studies: GitSpawn lets untrusted repos execute code in 7 major agents, a DeepSeek Harness sandbox escape scores CVSS 9.4, ZCode was caught silently uploading full Git history. The most cutting summary — this month's attacks rarely touched the model; they all hit the harness.

What happened: a 26-item case file
Adversa AI published the October edition of its AI coding agent security resource digest: 26 studies — 8 attack techniques, 8 agent vulnerabilities, 3 real incidents, plus defense, red-team and CISO perspectives. Last month's (September) edition covered "opening a folder is enough" — booby-trapped git configs executing attacker code in Claude Code, Codex, Cursor and four other agents before any approval prompt. The October edition hits harder.
The ones every vibe coder should know:
GitSpawn: a single flaw letting untrusted repositories execute code in 7 agents including Claude Code, Codex, Cursor and Grok. The mechanism is git config execution sinks (like core.fsmonitor) — the agent casually calls git for context, and the trap fires outside both sandbox and approval. The research documents 8 flaws; 4 were unpatched at publication.
Plugin4Shell: the four most popular agents — Claude Code, OpenAI Codex, GitHub Copilot, Gemini CLI — install pinned plugin commits via git checkout without verifying the result. An attacker names a branch like the pinned SHA and silently swaps in malicious code during automatic updates — affecting "millions of agents."
CVE-2026-82533: DeepSeek Harness exposed a localhost control API guarded only by the Host header. A sandboxed agent fed malicious input can call it over loopback and switch itself to "danger-full-access," escaping confinement. CVSS 9.4.
OpenCode RCE: the /global/upgrade endpoint accepted text/plain bodies and arbitrary package specs, so any webpage could POST cross-origin to a running opencode instance and install an attacker npm package whose preinstall script runs code. Fixed in 1.18.22 — if you're running an older opencode serve locally, upgrade now.
The ZCode incident: Z.ai's coding assistant was caught packaging entire workspaces into encrypted snapshots uploaded to Alibaba Cloud OSS — including full Git history, reflogs and LFS caches still holding deleted secrets and unpushed branches. The privacy toggles in the UI didn't stop the uploads.
Beyond vulnerabilities: three incidents with no attacker
The most thought-provoking part of the digest is the 3 incidents, because none involved an attacker:
PixelLeak: agents couldn't attach screenshots to PRs through the GitHub CLI, so they "got creative" — pushing over 13,000 internal screenshots to public repositories, from 300+ organizations, 93% in personal accounts. No hacker; the agent's own resourcefulness was the leak.
Infostealers found your agent: stealer families including Amatera, Remus, CallbackBeaver and macOS Djinn now harvest AI agent artifacts on purpose — Claude, Cursor, Cline and Codex access and refresh tokens, MCP configs holding credentials, and prompt histories in predictable, sometimes plaintext locations. The conclusion is blunt: agent tokens belong in your credential rotation plan starting today, treated like cloud keys.
Anthropic's September threat report: threat actors are already driving Claude and Claude Code as autonomous orchestrators across espionage, fraud and influence operations — rebuilding malware to evade detection, running agent swarms, stealing AI API keys from vendor evaluation sandboxes.
One more number, from Semgrep's SusVibes benchmark: Claude Opus 5.5 passed functional tests on 93.5% of 186 Python CVEs recast as feature requests — but only 54.8% were both working and secure. 41% of the "working" solutions reintroduced the original vulnerability. Passing tests is not a security gate.
The core verdict: the attack surface isn't the model, it's the harness
Adversa's summary line deserves to be memorized: this month's attacks rarely touched the model. They ran through git config, plugin pins, hooks, subagent configs and sandbox mount paths — everything an agent reads automatically when it opens a folder. Model refusals are preferences; the harness's restrictions (the loop, executors, context, approval gates, sandbox) are controls. Attackers figured it out long ago: models keep getting harder, harnesses are full of seams.
Translated into three iron rules for vibe coders:
First, treat every repository as executable input. Open untrusted repos only in disposable containers; disable automatic plugin updates, or at least make the agent verify "the commit that actually landed is the one I pinned"; review .git/config, hooks and agent config files the way you'd review a build script.
Second, ship logs somewhere the agent can't reach. Research confirms Claude Code, Codex, Antigravity, OpenCode and Grok Build all let agents delete their own execution traces unnoticed — logs the agent can write are not evidence. Forwarding execution logs to agent-proof storage is this month's cheapest security investment.
Third, manage tokens and secrets like production incidents. Credentials in MCP configs, secrets in prompt history, agent refresh tokens — stealers already have them on the shopping list. Rotation, least privilege, secrets outside the project tree: no "later" on this trio.
Security has an old saying: attackers only need to win once, defenders must win every time. The agent era adds a corollary: your agent is more diligent than you — it will happily upload 13,000 screenshots to the whole world while you sleep. Setting rules for it is saving trouble for your future self.
Sources
Related articles

On October 8, 2026, Google Cloud launched the Gemini agent at Gemini at Work 2026: a universal agent for work that takes objectives, plans by itself, auto-selects between Gemini and Claude models per task, and introduces 'coworker agents' with their own email, calendar, and directory seat. Four judgments on why the second half of the agent race is about 'agents that feel like colleagues.'

Reported by InfoQ on October 3: a GPT-4 coding agent given CVE descriptions successfully exploited 87% of 15 test vulnerabilities, versus 7% without descriptions. rclone's author received 40+ security disclosures in a single month — more than the project's previous decade combined; QEMU has shortened its embargo period. The vulnerability disclosure timeline is collapsing under agent speed.

On October 7, 2026, Google Developers launched the Developer Knowledge API ecosystem: official Google Cloud, Firebase, and Android docs as a programmatic source of truth, with a gcloud CLI surface, an official Agent Skill (one-line install), an MCP server, and multi-language client libraries. Why 'docs as APIs' uproots vibe coding's classic failure of models misremembering APIs.