AI coding agents can be prompt injected via README files, leading to code execution

alex_verem · x · 2026-08-03

The AI Now Institute disclosed that AI coding agents can be weaponized through README files. Prompt injections embedded in READMEs, config files, or code comments can steer autonomous coding agents into executing attacker-controlled code. Agents treat all files in a repository as trusted context, unable to distinguish user directives from attacker-planted instructions. A config saying 'run this setup script' looks routine, but the agent executes it and the script phones home. Varonis Threat Labs found a similar flaw in Google Cloud's Dialogflow CX, where basic update permissions allowed code injection affecting other agents.

Original post →

More from coding & agent

coding & agent channel →