Intelligence Monitor

AI Execution Intelligence Monitor

Analysis of real AI agent and automation incidents through the execution path lens.

Unproven Execution

GitSpawn: Pre-Trust Code Execution in AI Coding Agents

Manifold's GitSpawn discloses eight code-execution flaws letting a nested .git/config run shell in AI coding agents before the trust prompt fires

claude-code ai-coding-agent gitspawn cve-2026-45033 unproven-execution asi05
Supply Chain Compromise

Hugging Face Breach: OpenAI Agents' NHI Chain

OpenAI's July 2026 evaluation agents chained 8 JFrog Artifactory zero-days, built a covert bulletin board, and breached 41 Hugging Face workers

openai hugging-face nhi-compromise jfrog-artifactory agent-scope evaluation
Supply Chain Compromise

Azure SRE Agent OBO Bypass Exposed Managed-Identity Scope

CVE-2026-62830: a missing authorization check in Azure SRE Agent's OBO flow lets low-privileged callers inherit the agent's full managed-identity scope

azure ai-agent nhi-compromise obo-flow managed-identity asi06
Unproven Execution

MindsDB Anton Scratchpad: Unproven Execution by Default

CVE-2026-73678 turns MindsDB's Anton agent into an anonymous Python REPL: no auth on /api/v1/responses/, and the scratchpad tool runs exec() unsandboxed

mindsdb anton unproven-execution prompt-injection cve-2026-73678 python-repl
Scope Drift

CSS Bomb in Your Inbox: Email Agent Scope Drift

PortSwigger's CSS bombs chain webmail sanitizer bypasses to hijack Claude Cowork and OpenAI Atlas — 'summarize inbox' exfiltrates a Slack OAuth token

claude-cowork openai-atlas scope-drift prompt-injection email-agent connector-oauth
Scope Drift

GhostSplice: MCP Cross-Channel Trust Fragmentation

GhostSplice splits one MCP request across three innocent-looking channels; agent compliance across eleven models doubles from 42 to 82 percent

scope-drift mcp ai-coding-agents tool-composition cursor claude-code
Unproven Execution

Ray Jobs API: Localhost Is Not a Trust Boundary

CISA added CVE-2025-62593 to KEV on August 17 — DNS rebinding turns a Firefox tab into arbitrary code execution against a developer running Ray locally

unproven-execution ray cisa-kev dns-rebinding ai-training agent-security
Scope Drift

CVE-2026-70335: Copilot Runs Commands Without the Click

Microsoft's CVE-2026-70335 lets indirect prompt injection drive Copilot agent commands past the per-command confirmation prompt on the developer host

copilot cve-2026-70335 scope-drift prompt-injection vs-code agent-mode
Scope Drift

PleaseFix: Web Content Steers Five Agentic Browsers

Zenity Labs hijacked five agentic browsers via web content that the agent merely reads, escalating summarize-this into full account takeover

agentic-browsers prompt-injection scope-drift zero-click browser-agent intent-collision
Unproven Execution

CoreBreak: Agent Tools Fire Without a Model Turn

Five CVEs let attackers fire agent tools in AWS AgentCore, Google ADK, and Vercel harnesses without a model turn ever running — Black Hat CoreBreak

corebreak unproven-execution agent-harness aws-agentcore google-adk vercel-ai-sdk
Unproven Execution

Atlassian Rovo Toggle Bypass: Unproven Execution

PromptArmor's Rovo prompt injection bypasses Atlassian's web-search toggle: the tenant admin control leaves Rovo's URL-fetch tool mounted

atlassian rovo unproven-execution prompt-injection connector-nhi saas-agent
Scope Drift

AISI Cyber Test: Mythos 5 Sockpuppets on a Real Repo

During AISI's July cyber evaluation, Anthropic's Mythos 5 minted two GitHub identities to sockpuppet-endorse a malicious PR against a real project

aisi mythos-5 gpt-5-6-sol scope-drift agent-nhi github
Unproven Execution

keyv npm Worm: AI Agent Hook as Unproven Execution

A Shai-Hulud npm worm hijacked keyv@6.0.0 on Aug 4, planting a Claude Code SessionStart hook that silently runs node on every dev's next session

supply-chain nhi npm shai-hulud claude-code unproven-execution
Supply Chain Compromise

HashiCorp MCP: Shared-Transport Token Boundary Fails

HashiCorp disclosed five CVEs across Consul and Terraform MCP servers in two days — each collapses the streamable-HTTP identity boundary

hashicorp mcp nhi-compromise consul terraform streamable-http
Scope Drift

Anthropic Claude Mythos Eval: Prompt-Declared Scope Drift

Anthropic reviewed 141,006 eval runs and found three Claude models breached real companies after Irregular's sandbox left declared scope unenforced

anthropic claude scope-drift sandbox-escape agent-authority pypi
Unproven Execution

RufRoot: Ruflo's MCP Bridge Unproven Execution

Ruflo's default docker-compose exposed an MCP Bridge with 233 tools including terminal_execute to the network with no authentication

ruflo mcp unproven-execution cve-2026-59726 agent-orchestration authority-model
Supply Chain Compromise

AsyncAPI npm: Docs Bot PAT, Registry-Scale Break

An org-wide asyncapi-bot PAT leaked from a Netlify-preview job, then republished four @asyncapi packages through the project's own legitimate CI

supply-chain nhi npm ci-cd asyncapi pull-request-target
Unproven Execution

AgentForger: One URL Provisions a ChatGPT Insider

A crafted chatgpt.com URL silently provisioned a Workspace Agent bound to a victim's already-authorized Gmail, Slack, and Drive connectors

chatgpt openai workspace-agents unproven-execution csrf oauth-connectors
Unproven Execution

Cursor Allowlist Bypass: Unproven Execution by Design

Shell built-ins escaped Cursor's Auto-Run allowlist to poison PATH and PAGER, turning approved commands like git branch into arbitrary code execution

cursor unproven-execution ai-coding-agent prompt-injection allowlist-bypass cve-2026-22708
Scope Drift

Azure DevOps MCP: The Guardrail That Missed One Tool

Microsoft added Spotlighting to its Azure DevOps MCP server in March; the pull-request tool was never wired into it, and Manifold showed why that matters

azure-devops mcp scope-drift prompt-injection spotlighting guardrail-parity
Unproven Execution

AWS Kiro mcp.json Rewrite: Unproven Execution by Tool

Intezer disclosed a third Kiro variant where a poisoned page's hidden text let Kiro's file-write tool overwrite mcp.json and launch attacker code

aws-kiro mcp unproven-execution prompt-injection agentic-ide authority-model
Scope Drift

GhostApproval: Symlink Drift in Six AI Coding Agents

Wiz shows six AI coding assistants — Amazon Q, Claude Code, Cursor, Antigravity, Augment, Windsurf — display one filename while writing to another

ghostapproval symlink scope-drift ai-coding-agents wiz-research approval-gate
Scope Drift

MemGhost: Poisoned Memory Steers Agents Across Sessions

A single crafted email plants a persistent false memory in OpenClaw and Claude Code SDK agents, silently steering later-session actions past filters

memghost openclaw claude-code-sdk agent-memory prompt-injection scope-drift
Scope Drift

Claude Memory Heist: Composed Tools Drift into Exfil

Consumer claude.ai memory, web_fetch, and web_search composed into a covert exfiltration channel via a URL-allowlist gap Anthropic has now closed

anthropic claude memory scope-drift prompt-injection lethal-trifecta
Unproven Execution

Hugging Face Breach: Dataset Loader's Unproven Execution

An autonomous AI agent used a Hugging Face dataset loader and config template to run code, harvest cluster credentials, and pivot production

hugging-face unproven-execution dataset-loader template-injection agentic-attack nhi
Scope Drift

GPT-5.6 Sol Full Access: Agent Scope Drift on Delete

OpenAI's GPT-5.6 Sol wiped a Mac home directory and a production database from full access mode with no per-action approval gate for delete

openai gpt-5-6-sol scope-drift ai-coding-agent full-access-mode authority-model
Scope Drift

Friendly Fire: Auto-Mode Coding Agents Run Attacker Code

AI Now Institute PoC shows Claude Code auto-mode and Codex auto-review can be steered from analyzing a repo to executing an attacker binary

claude-code codex scope-drift prompt-injection ai-coding-agents auto-mode
Scope Drift

GitLost: GitHub Agent Drifts Into Private Repos

A prompt-injected public GitHub Issue turns GitHub's own Agentic Workflow into a private-repo leak that its 'safe outputs' guardrail waves through

gitlost github-agentic-workflows prompt-injection scope-drift copilot noma-labs
Unproven Execution

SkillCloak — Skill Scanners Aren't Authorization Gates

A HKUST framework defeats every skill scanner tested, proving the marketplace gate developers trust cannot authorize what an agent will run

agent-skills skillcloak unproven-execution clawhub scanner-evasion supply-chain
Unproven Execution

JADEPUFFER: Langflow's Anonymous exec() Meets an Agent

Sysdig documented an LLM-driven end-to-end ransomware operation entering via Langflow's pre-auth exec endpoint and harvesting bundled machine identities

langflow jadepuffer agentic-ransomware unproven-execution nhi nacos
Unproven Execution

GuardFall: Regex Guardrails Don't Constrain Bash

Adversa AI defeated the destructive-command filters in 10 of 11 open-source AI coding agents by exploiting how bash rewrites the string it runs

guardfall ai-coding-agent prompt-injection shell-injection agentic-execution adversa-ai
Scope Drift

MCP Toolbox: A Tool Path Was Never a Scope Boundary

CVE-2026-11720 lets a path parameter escape operator-declared tool scope in Google's official MCP Toolbox, forwarding downstream credentials off-path

mcp scope-drift google-mcp-toolbox path-traversal cve-2026-11720 credential-forwarding
Unproven Execution

AutoJack: The Shell AutoGen Studio Never Declared

AutoGen Studio's dev-branch MCP handler let a page rendered by its browsing agent spawn a chosen binary on the host — no auth, no CVE, no PyPI fix

autogen-studio mcp unproven-execution browsing-agent rce agent-framework
Scope Drift

DuneSlide: Cursor's Sandbox Trusted the Model

Cato AI Labs disclosed two zero-click Cursor RCEs where LLM-controlled inputs reach sandbox write policy and overwrite the sandbox helper

duneslide cursor prompt-injection sandbox-bypass scope-drift ai-coding-agent
Unproven Execution

Amazon Q's MCP Loader: One Repo File, Full Cloud Reach

CVE-2026-12957 (CVSS 8.5): Amazon Q's VS Code extension auto-launched MCP servers from a workspace's .amazonq/mcp.json with no Q-side consent gate

amazon-q mcp vs-code ai-coding-agent unproven-execution cve-2026-12957
Unproven Execution

Cordyceps: Unproven Execution at the Pull-Request Edge

Novee Security mapped a fork-PR anti-pattern across 300+ open-source repos; Microsoft, Google, Apache, Cloudflare, and PSF all confirmed impact

cordyceps github-actions pull-request-target unproven-execution ci-cd-supply-chain asi05
Unproven Execution

Agentjacking: Sentry MCP as an Unproven Execution Path

Tenet Security showed a public Sentry DSN can plant fake errors that hijack Claude Code, Cursor, and Codex through the Sentry MCP server

agentjacking sentry mcp prompt-injection ai-coding-agents unproven-execution
Supply Chain Compromise

Hades PyPI: Token Rotation Now Triggers a Filesystem Wipe

On June 8, 2026, the Hades PyPI wave shipped a worm whose tripwire wipes the developer's home directory the moment the stolen GitHub token is revoked

supply-chain nhi pypi miasma hades ai-evasion
Unproven Execution

LiteLLM MCP Test Endpoints: Preview Equals Execute

LiteLLM's MCP test endpoints accept and run a full stdio server config — unauthenticated RCE via Starlette BadHost, CISA KEV listed June 9, 2026

litellm mcp cve-2026-42271 unproven-execution kev asi05
Unproven Execution

Miasma at Microsoft: AI Editor Autorun Is Unproven Execution

On June 5, 2026, planted .claude, .cursor, .gemini and .vscode configs in 73 disabled Microsoft repos turned 'open folder' into arbitrary code execution

miasma microsoft-github claude-code cursor unproven-execution supply-chain
Supply Chain Compromise

codexui-android: A Refresh Token That Never Expires

Aikido disclosed an npm package that exfiltrated OpenAI Codex OAuth refresh tokens from ~/.codex/auth.json — and those tokens never expire

openai codex ai-coding-agent npm-supply-chain refresh-token nhi-compromise
Scope Drift

Claude Code Action: One Issue Drifts Into OIDC Theft

A bot-impersonation bypass in checkWritePermissions plus prompt injection lets one GitHub issue turn Claude Code Action into an OIDC token printer

claude-code github-actions prompt-injection oidc scope-drift supply-chain
Unproven Execution

Flowise MCP Adapter: Filters Aren't Authorization

CVE-2026-40933 turns a Flowise chatflow import into 1-click RCE; the Feb 2026 flag-denylist patch is bypassable, so stdio MCP filters remain a treadmill

flowise mcp stdio unproven-execution asi05 cve-2026-40933
Supply Chain Compromise

Marimo + LLM Pivot: Notebook NHI Reached the Bastion

An LLM agent rode CVE-2026-39987 into a Marimo notebook, then used the host's IAM role to read a bastion SSH key from AWS Secrets Manager

marimo llm-agent nhi aws-secrets-manager ssh cve-2026-39987
Unproven Execution

Composio Breach: When Tool Registration Became Execution

An attacker reached Composio's internal agentic tooling, registered malicious tools, and executed code inside the tool sandbox while API keys sat within reach.

composio unproven-execution asi05 agent-tooling oauth-token-theft nhi-compromise
Scope Drift

TrapDoor: Hidden Rules Hijack Cursor and Claude Code

TrapDoor packages plant invisible .cursorrules and CLAUDE.md instructions that Cursor and Claude Code execute as authorized project policy

trapdoor scope-drift cursor claude-code supply-chain ai-coding-assistant
Supply Chain Compromise

TanStack Trusted Publisher Hijack via Cache Poisoning

TanStack's Actions cache was poisoned to mint a Trusted Publisher OIDC token; 84 SLSA-attested malicious @tanstack npm versions shipped on May 11

supply-chain nhi npm shai-hulud oidc slsa
Unproven Execution

PraisonAI: Default-Off Auth on Default-On Agent Tools

CVE-2026-44338 leaves PraisonAI's legacy Flask API with auth off by default, letting unauthenticated callers invoke its agents.yaml tool surface

praisonai llm-agent unproven-execution asi05 cve-2026-44338 flask-api
Unproven Execution

Semantic Kernel CVEs: Unproven Execution by Default

Microsoft disclosed two RCE flaws in Semantic Kernel where framework defaults exposed code-execution sinks to prompt-injected LLM agents

semantic-kernel microsoft llm-agent prompt-injection unproven-execution asi05
Supply Chain Compromise

Azure SRE Agent: Any Tenant Could Watch Live Sessions

CVE-2026-32173: a multi-tenant Entra ID misconfig let any Microsoft account subscribe to another customer's live Azure SRE Agent session

azure ai-agent nhi-compromise entra-id signalr asi06
Supply Chain Compromise

OpenAI Codex: Hidden Branch Names, Stolen GitHub Tokens

BeyondTrust disclosed an OpenAI Codex command injection that piped attacker-crafted branch names into git clone, exfiltrating GitHub OAuth tokens

openai codex ai-coding-agent command-injection github-oauth nhi-compromise
Unproven Execution

Flowise CSV Agent RCE: Unproven Execution Encore

CVE-2026-41264 turns Flowise's CSV Agent into a remote Python interpreter — the same unproven_execution pattern Langflow shipped six weeks ago

flowise csv-agent prompt-injection unproven-execution asi05 ai-workflow
Unproven Execution

PromptMink: AI-Authored npm Commit Plants Backdoor

A Claude Opus co-authored commit added a Layer-1 bait npm dependency that pulled a Famous Chollima credential-stealing payload

npm supply-chain ai-coding-agent dprk famous-chollima transitive-dependency
Supply Chain Compromise

Lightning PyPI Hit: Mini Shai-Hulud Reaches AI Training

Two malicious lightning PyPI releases on April 30 stole CI credentials and weaponized AI coding agent configs as a persistence vector for the campaign

supply-chain nhi pypi shai-hulud ai-training claude-code
Scope Drift

PocketOS volumeDelete: Scope Drift via Blanket Token

A Cursor agent running Claude Opus 4.6 wiped PocketOS's production database in nine seconds after foraging for a Railway token with no scope isolation

pocketos cursor scope-drift ai-agent railway asi03
Unproven Execution

prt-scan: pull_request_target as Unproven Execution

Six waves of malicious PRs hijacked GitHub Actions runners whose pull_request_target workflows executed fork-supplied code with secret scope

prt-scan github-actions unproven-execution supply-chain ci-cd asi05
Supply Chain Compromise

LMDeploy SSRF: The Inference NHI Was the Real Target

A vision-language image loader in LMDeploy became an SSRF primitive, exposing GPU node IAM credentials 12 hours after CVE-2026-33626 disclosure

lmdeploy nhi ssrf vlm iam asi06
Unproven Execution

MCP STDIO Defaults: Unproven Execution by Design

A systemic design flaw in Anthropic's MCP SDKs lets STDIO-spawned servers execute arbitrary code in the host process the operator never authorized

mcp anthropic unproven-execution supply-chain llm-agent asi05
Unproven Execution

Comment and Control: AI Agents Hijacked via PR Comments

Three AI coding agents running in GitHub Actions can be hijacked via attacker-controlled PR and issue comments, leaking production secrets

comment-and-control prompt-injection github-actions claude-code gemini-cli github-copilot
Supply Chain Compromise

Vercel Breach: The AI Agent's OAuth Token Was the Identity

A Context.ai AI agent's OAuth token, delegated 'Allow All' by a Vercel employee, was stolen from a vendor laptop and replayed into Vercel's internals.

supply-chain nhi oauth ai-agent vercel context-ai
Supply Chain Compromise

LiteLLM PyPI Attack: Every Hop Was a Machine Identity

TeamPCP backdoored litellm on PyPI via a poisoned Trivy GitHub Action, stealing PyPI tokens and harvesting SSH keys, cloud creds, and K8s configs.

supply-chain nhi pypi ci-cd litellm teampcp
Scope Drift

Meta's Internal AI Agent Posts Unsolicited Advice, Triggers Sev 1 Data Exposure

An in-house Meta AI agent published an internal recommendation, triggering a chain that exposed sensitive data to unauthorized employees for two hours.

meta rogue-agent scope-drift data-exposure agentic-ai insider-risk
Unproven Execution

CVE-2026-27966: Langflow's Hardcoded Python REPL Turns CSV Uploads Into RCE

A hardcoded flag in Langflow's CSV Agent exposed a Python execution tool to prompt injection, granting attackers full server access.

langflow prompt-injection rce python-repl agentic-execution