Plugin4Shell: AI coding agents don’t verify what they install

a computer screen with a bunch of code on it

SHA pinning is supposed to be the safe move. Lock a plugin to a specific commit hash, review it once, and trust that what your agent installs is what you approved. A new vulnerability called Plugin4Shell breaks that assumption entirely.

What Researchers Found

Or Nevo, Dor Granat, and Niv Hoffman at AIR Security discovered that four major AI coding agents check out a pinned commit but never confirm the checkout actually landed on that exact hash afterward. That single missing verification step is the whole attack surface.

An attacker who controls a plugin’s repository can swap in malicious code between the pin and the install. The agent proceeds as if nothing changed, still believing it installed the reviewed version.

Which Agents Are Affected

  • Claude Code (Anthropic)
  • GitHub Copilot
  • Gemini (Google)
  • OpenAI Codex

AIR Security disclosed working proof-of-concept exploits against all four. No reporting so far claims Plugin4Shell was used in an actual attack before it went public.

The Operator Takeaway

If you use any of these agents with third-party plugins, SHA pinning alone is no longer sufficient. The fix has to come from the agent vendors in the form of post-checkout hash verification. Until patches ship, treat unverified plugin installs as untrusted code regardless of what the agent reports.

Stay on top of AI & Automation with BizStack Newsletter
BizStack  —  Entrepreneur’s Business Stack
Logo