Plugin4Shell: a reviewed plugin didn't stay reviewed. What your security team should check now.

You did the careful thing. You picked a plugin from a trusted marketplace. Someone reviewed it. The marketplace pinned the exact version that was reviewed. Plugin4Shell showed that none of that held.
What happened
Researchers at Air Security found one flaw in Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI. Each agent checked out the pinned commit of a plugin. None verified that the checkout actually landed on it1.
An attacker who controlled the plugin's repository could make a branch named exactly like the pinned commit hash. Then set it as the default. Git would check out the attacker's branch. The agent would report the reviewed version as installed. Claude Code and Codex auto-update plugins by default. So the swap would reach machines that already had the plugin. No prompt. No click1. Air built working exploits against all four agents. Neither source reports the attack being used in the wild.
It needs a git host that allows branch names shaped like a hash. GitHub rejects them. Bitbucket and self-hosted git servers allow them1.
Air found the bug in May. It disclosed it to all four vendors in June. Anthropic fixed Claude Code in version 2.1.179. OpenAI fixed Codex in 0.146.0. Google deprecated Gemini CLI instead of patching it. It advises users to move to Antigravity. As of Help Net Security's report on 18 September, Microsoft had not shipped a fix for Copilot12.
Why this matters if you don't run coding agents
Your invoice agent is not Claude Code. But it probably loads things. A connector to your ERP. A skill for reading PDFs. A tool server someone found on GitHub. Each of those runs with whatever access the agent has. If the agent can post journal entries, so can the plugin.
Plugin4Shell shows the gap cleanly. Install-time review answers "was this code safe when we looked at it?" It does not answer "is this the code running now?" And it says nothing about what the code does once it runs. With the agent's permissions.
Anthropic's September threat report makes the same point from the other side. Attackers stole AI API keys from companies' own systems. They ran their operations on them. The report tells organisations to treat "AI keys and agent integrations" as seriously as production credentials3.
What to check now
- /01
Patch the coding agents. Claude Code at 2.1.179 or later. Codex at 0.146.0 or later. Plan to remove Gemini CLI. Do your developers use Copilot plugins from non-GitHub marketplaces? Ask your Microsoft contact for a date.
- /02
List what your agents load. Take every agent that can change a record, send a message or move money. Write down each plugin, skill, connector and tool server. Where it comes from. Who can push a new version. If it takes more than an afternoon, write that down. It's your first finding.
- /03
Turn off silent updates where the agent can act. Updates to anything with write access go through the same change control as the agent itself. A named person signs.
- /04
Give add-ons no more than the agent's job needs. A PDF reader does not need your ERP token. If your setup can't split them, fix that before the next incident.
- /05
Check actions as well as installs. A compromised plugin still has to act through the agent. Check every action against a fixed scope before it runs. A plugin tries to email your vendor master to a stranger. It gets refused. Whatever version is installed.
That fifth point is the one install-time review can't cover. It is how Gatehouse is built. Scope comes from a signed rules file. Each action is checked before it runs. A refused action is saved in the record with the reason. Already run an agent and want this layer around it? Start at govern the agent you already run.
Start with the list in step 2. Put it in front of your security lead this week. Before an update does it for you. Our vendor questions cover what to ask next.
Sources
Want the next one? News with a take, three times a week. Follow by RSS
Read next
What should you ask an AI vendor before signing?
Twelve questions that separate a system you can run from a demo you can't control. Ask us first.

Prompt injection in accounts payable: what an invoice can tell your agent to do
An invoice is text a stranger wrote, and your agent reads all of it. Prompt injection turns that text into instructions. You can't filter it out. You can limit what it can do.

What is an agent approval policy?
An approval policy decides which agent actions go ahead, which wait for a person, and which never happen. Most teams have a paragraph. You need a table.