Same Flaw Found in Claude Code, Codex, Gemini CLI and GitHub Copilot
Startup Air found the same flaw in how four AI coding agents from Anthropic, OpenAI, Google and Microsoft handle skills. The vulnerability allowed hijacking another user's agent without the owner noticing; it is now mostly fixed.
- Flaw affects Claude Code, Codex, Gemini CLI and GitHub Copilot
- Issue found in processing of skills — instructions and task files
- Attack allowed silently hijacking another user's coding agent
- Research conducted by startup Air, backed by Sequoia Capital
Read next
Security