AI coding agents can be prompt injected via README files, leading to code execution
alex_verem · x · 2026-08-03
The AI Now Institute disclosed that AI coding agents can be weaponized through README files. Prompt injections embedded in READMEs, config files, or code comments can steer autonomous coding agents into executing attacker-controlled code. Agents treat all files in a repository as trusted context, unable to distinguish user directives from attacker-planted instructions. A config saying 'run this setup script' looks routine, but the agent executes it and the script phones home. Varonis Threat Labs found a similar flaw in Google Cloud's Dialogflow CX, where basic update permissions allowed code injection affecting other agents.
More from coding & agent
- Echoverse: Training Agents in Deep Environments Boosts 9B Model Success Rate to 67% — burny_tech · 2026-08-03
- Architecting a Yoga Studio Chatbot: Multi-Model Routing and Low-Cost Memory — omi0009 · 2026-08-03
- Autoexp: A Local-First AI-Assisted Experimentation Workspace — Southern-Whereas3911 · 2026-08-03
- Discussion: Browser Agents Waste Too Many Tokens on UI Navigation — Opening-Profile6279 · 2026-08-03
- Developer Integrates Claude into git-cz for Automated Commit Messages — 4310sy · 2026-08-03
- GPT-5.6 Luna Max Underperforms as a Codex Subagent, Dev Finds — daniel_mac8 · 2026-08-03