Same Flaw Found in Claude Code, Codex, Gemini CLI and GitHub Copilot

While the AI industry ties itself in knots over models it thinks will pose security threats to the internet and perhaps to humanity itself, researchers are warning about flaws in AI coding agents from Anthropic, OpenAI, Google and Microsoft that pose immediate risk to businesses.

For instance, a recently discovered (and now largely fixed) software flaw in Claude Code, Codex, Gemini CLI and GitHub Copilot would have let attackers hijack other people’s coding agents without them noticing, according to new research shared exclusively with The Information.

The research, published by Sequoia Capital-backed cybersecurity startup Air, discovered the same flaws in the way all four of those coding agents handle “skills” that direct agents to refer to a set of instructions and files to execute specific tasks.

“It’s very rare to find one vulnerability that affects four of the top AI coding agents,” said Air founder and CEO Niv Hoffman. “It means four different engineers in four different companies made the same exact logical mistake, and this mistake was in how they built their verification mechanism.”

Other security startups have found similar vulnerabilities stemming from skills in recent months.

Skills, which are akin to downloadable browser extensions, are popular among super users that want their AI agents to browse the internet or design code bases in specific ways, for example. Many workers download skills created by other people and stored in open source repositories. Anthropic and Microsoft also offer such skills.

All four coding agent providers try to detect malicious code in skills. But after a customer downloads a skill and it goes through those coding agents’ scanners, the agent tool automatically installs software updates released by the skill’s creator. Air discovered that if a hacker updated a skill with malicious code and gave it the same name as the previous version of that skill, the AI coding agents would automatically download the malicious update without detecting the change or alerting the customer.

That means all a hacker would have to do is upload a skill to a public marketplace that appeared useful and benign, wait for people to use it, then change the skill to include malicious code for stealing IP, for instance.

Air hasn’t seen any evidence that the vulnerability was exploited by hackers before the startup reported it to the companies in June, Hoffman said. Microsoft hasn’t confirmed it patched the flaw in GitHub Copilot, Hoffman said. The other three providers have done so.

A GitHub spokesperson did not comment directly on the vulnerability in GitHub Copilot, but said that attackers wouldn’t be able to host such malicious skills in GitHub repositories because GitHub prevents users from reuploading different software using the same name. Spokespeople for Google, OpenAI, and Anthropic did not comment.

The findings show how companies need to be cautious about how their employees use skills for their coding agents, said Ken Huang, an AI security consultant and adjunct professor at the University of San Francisco.

“You could argue that the warnings about AI security we’re hearing about in the next six to 12 months may be overhyped, but the security issues with these AI agents are in many ways underhyped,” Huang said. “AI agent skills are widely used by knowledge workers, but this shows skills can be captured even when they appear trustworthy.”

Salesforce CEO Dismisses Data Fears

Salesforce CEO Marc Benioff on Wednesday dismissed concerns from Palantir CEO Alex Karp that model providers Anthropic and OpenAI could effectively steal their corporate clients’ business data, a topic we reported on Monday.

“When we hear other vendors say, ‘Well if you’re using such and such model, you’re giving them your intellectual property,’ that is not true,” CEO Marc Benioff told analysts during a presentation at his company’s annual Dreamforce event in San Francisco. “When you’re being told some of these things, you have to remember people have their own agendas that they’re trying to get you to act in a certain way.”

At the same time, the executive took the opportunity to highlight Salesforce’s zero data retention policy, in which it does not share its customers’ data with AI model providers like Anthropic that power its products. As we pointed out in our Monday piece, Anthropic has changed its zero data retention policies for its most advanced models, and customers worry about the company seeing their most sensitive information. They also worry that, without ZDR guaranteed in their contracts, Anthropic could change the rules for data retention whenever it wants. So it’s not quite as simple as Benioff makes it out to be.

HubSpot, Salesforce Joins ‘Harness’ Movement

Just a few months ago, the term “harness,” referring to software that helps AI agents use the right tools and models to perform tasks more cost effectively, was reserved for technical engineering types.

Now the term is making its way into the mainstream, especially among software companies that want to position themselves as neutral intermediaries between enterprises and AI model providers.

Salesforce spent a chunk of time during Dreamforce showing off its own enterprise harness that gives customers’ AI agents’ the right skills and permissions to take actions in their Salesforce accounts.

Salesforce’s smaller CRM rival, HubSpot, revealed its own harness, Aviator, this week at its own customer conference in Boston, Duncan Lennox, chief product and technology officer, told us. The harness wasn’t mentioned in HubSpot’s promotional press materials, but Lennox said Aviator is central to HubSpot’s AI strategy.

The harness is a software layer that picks the right tools and models for HubSpot’s AI agents to cost-effectively perform tasks involving the CRM software, such as generating ads and emails for marketing teams. HubSpot has been working on the harness for three years, Lennox said, and it routes tasks to be powered by different AI models, including OpenAI’s, depending on the complexity of the tasks.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论