surehand
All articlesSecurity

Plugin4Shell: a reviewed plugin didn't stay reviewed. What your security team should check now.

News3 min readSurehand

You did the careful thing. You picked a plugin from a trusted marketplace. Someone reviewed it. The marketplace pinned the exact version that was reviewed. Plugin4Shell showed that none of that held.

What happened

Researchers at Air Security found one flaw in Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI. Each agent checked out the pinned commit of a plugin. None verified that the checkout actually landed on it1.

An attacker who controlled the plugin's repository could make a branch named exactly like the pinned commit hash. Then set it as the default. Git would check out the attacker's branch. The agent would report the reviewed version as installed. Claude Code and Codex auto-update plugins by default. So the swap would reach machines that already had the plugin. No prompt. No click1. Air built working exploits against all four agents. Neither source reports the attack being used in the wild.

It needs a git host that allows branch names shaped like a hash. GitHub rejects them. Bitbucket and self-hosted git servers allow them1.

Air found the bug in May. It disclosed it to all four vendors in June. Anthropic fixed Claude Code in version 2.1.179. OpenAI fixed Codex in 0.146.0. Google deprecated Gemini CLI instead of patching it. It advises users to move to Antigravity. As of Help Net Security's report on 18 September, Microsoft had not shipped a fix for Copilot12.

Why this matters if you don't run coding agents

Your invoice agent is not Claude Code. But it probably loads things. A connector to your ERP. A skill for reading PDFs. A tool server someone found on GitHub. Each of those runs with whatever access the agent has. If the agent can post journal entries, so can the plugin.

Plugin4Shell shows the gap cleanly. Install-time review answers "was this code safe when we looked at it?" It does not answer "is this the code running now?" And it says nothing about what the code does once it runs. With the agent's permissions.

Anthropic's September threat report makes the same point from the other side. Attackers stole AI API keys from companies' own systems. They ran their operations on them. The report tells organisations to treat "AI keys and agent integrations" as seriously as production credentials3.

What to check now

  1. /01

    Patch the coding agents. Claude Code at 2.1.179 or later. Codex at 0.146.0 or later. Plan to remove Gemini CLI. Do your developers use Copilot plugins from non-GitHub marketplaces? Ask your Microsoft contact for a date.

  2. /02

    List what your agents load. Take every agent that can change a record, send a message or move money. Write down each plugin, skill, connector and tool server. Where it comes from. Who can push a new version. If it takes more than an afternoon, write that down. It's your first finding.

  3. /03

    Turn off silent updates where the agent can act. Updates to anything with write access go through the same change control as the agent itself. A named person signs.

  4. /04

    Give add-ons no more than the agent's job needs. A PDF reader does not need your ERP token. If your setup can't split them, fix that before the next incident.

  5. /05

    Check actions as well as installs. A compromised plugin still has to act through the agent. Check every action against a fixed scope before it runs. A plugin tries to email your vendor master to a stranger. It gets refused. Whatever version is installed.

That fifth point is the one install-time review can't cover. It is how Gatehouse is built. Scope comes from a signed rules file. Each action is checked before it runs. A refused action is saved in the record with the reason. Already run an agent and want this layer around it? Start at govern the agent you already run.

Start with the list in step 2. Put it in front of your security lead this week. Before an update does it for you. Our vendor questions cover what to ask next.

Sources

  1. [1]Air Security, Plugin4Shell: zero-click RCE in the top 4 coding agentsair.security In text
  2. [2]Help Net Security, Zero-click RCE vulnerability hit four major AI coding agents (18 September 2026)helpnetsecurity.com In text
  3. [3]Anthropic, Countering misuse of AI: September 2026anthropic.com In text

Want the next one? News with a take, three times a week. Follow by RSS

Read next

[ your next step ]

Bring us the queue nobody wants.

One process, studied in writing. You keep the document, whatever it says.

support@surehand.io