S

EPISODE · Jun 30, 2026 · 0 MIN

Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks

from Security Stuff · host Trace3

Adversa AI has discovered a major vulnerability in open source AI coding agents, dubbed GuardFall, that exploits decades-old Bash shell tricks to bypass security guards and execute malicious commands. Of eleven popular agents tested, only one—Continue—was able to block all the attack techniques, which use methods like quote removal and spacing manipulation to disguise destructive commands that the AI agent then executes with the developer's full authority. This creates a significant supply chain risk, especially in CI pipelines where auto-approval modes are common, potentially allowing attackers to exfiltrate credentials or wipe development environments through poisoned files in malicious repositories.

Episode metadata supplied by the publisher feed · Published Jun 30, 2026

Embed this episode

NOW PLAYING

Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks

0:00 0:50

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Security Stuff?

This episode is 0 minutes long.

When was this Security Stuff episode published?

This episode was published on June 30, 2026.

Can I download this Security Stuff episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!