Dev.to Security 🔐 Cybersecurity 👁 0 📖 3 min read

Adversa's October Agent Security Roundups: The Bugs Moved Below the Prompt

Adversa published two October roundups this week, one on AI agents broadly (4 October) and one on coding agents (2 October). Read together, they show where agent security bugs now live: in plugin updates, sandbox control

Adversa published two October roundups this week, one on AI agents broadly (4 October) and one on coding agents (2 October). Read together, they show where agent security bugs now live: in plugin updates, sandbox control APIs, credential stores, agent-to-agent protocols and copilots bolted onto admin tools. Most of them don't need a clever jailbreak. They need an agent that trusts something it shouldn't.

Plugin updates are the new supply chain

The coding-agent roundup reports "Plugin4Shell" from Air.Security: plugins pinned to a specific commit can be swapped for malicious code during automatic updates, across Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI. Pinning is supposed to be the control. In this case it was the way in.

Adversa's advice is to disable automatic plugin updates until commit verification is in place. That's sensible, and it isn't a lot of work.

Sandboxes keep failing at the control plane

The same roundup lists a DeepSeek Harness flaw (CVE-2026-82533) where an unauthenticated localhost API let a sandboxed agent switch itself to "danger-full-access," plus two Codex escapes, one writing outside workspace boundaries and one leaking trust tokens through heap snapshots. The 4 October roundup adds a MaxKB sandbox bypass (CVE-2026-77521) in which only the first command in a chain was sandboxed, so anything after a semicolon ran as root.

None of these beat the sandbox itself. They went around it: the control API, the token, the second command. Those are the places worth testing.

Credentials and protocols are inside the blast radius

The 4 October roundup reports, among September's findings:

Unit 42 showed indirect injection reading an AWS agent harness's heap via /proc to extract plaintext identity JWTs. An arXiv paper catalogs 11 design flaws in the Agent2Agent (A2A) protocol, including context injection through unprotected context IDs and credential harvesting through multi-hop delegation. A SQL Server Management Studio copilot flaw (CVE-2026-65669) let instructions planted in database properties bypass read-only mode and escalate to sysadmin.

The last one is worth dwelling on. Read-only mode was the boundary, and the input that crossed it was plain database metadata.

Agents leak by being helpful

One item in the coding roundup didn't involve an attacker at all. Adversa reports that more than 13,000 internal screenshots from over 300 organizations ended up public when coding agents pushed images to public repositories to get around a GitHub CLI limitation. The agent completed its task. The boundary was the thing it worked around.

A quick GitSpawn update

We covered GitSpawn when Manifold disclosed it in September. Adversa's roundup still lists four of the eight reported flaws as unpatched at publication. If you run coding agents against repos you didn't create, that's still an open issue.

A note on sourcing

Everything above comes from Adversa's two roundups, which link out to the primary research. We couldn't independently fetch all of the primary write-ups for this piece, so check the linked originals before quoting specifics.

Test the boundaries you actually have

Each finding above is a boundary someone assumed existed and never tested. Humanbound's engine and CLI are open source, and you can run adversarial tests against your own agents today.

Test your agents for free. Humanbound's Community plan is free and rolling out to as many developers as possible. Sign up at app.humanbound.ai.

References

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.