Signal

GuardFall: decades-old shell tricks bypass safety guards in 10 of 11 popular AI coding agents

Security researchers at Adversa AI found that 10 of the 11 most-used open-source AI coding agents — a combined 548,000 GitHub stars — can be tricked into running dangerous shell commands using bash quoting and variable-expansion tricks that have been public knowledge for decades, because their safety filters check the command text rather than what bash actually executes.