An empirical review of 3,171 public GitHub repositories found confirmed security defects in 16.0% of AI coding-agent harness configurations. The review covered 2,660 multi-component agent setups and 511 published skill collections, assessing instruction files, skills, hooks, subagents, and Model Context Protocol (MCP) server declarations. The most common issues were unpinned MCP server versions, overly broad execution pre-approvals, and skills that pre-authorized shell access for installers; researchers did not confirm a credential-exfiltration path.
The harness surrounding a coding model—its prompts, tools, skills, MCP servers, and orchestration—creates a material supply-chain and prompt-injection attack surface. Mutable remote MCP services, trusted prompt formatting, YAML skill metadata, and self-propagating payloads such as CopyPasta can be abused to influence agent actions. Organizations should inventory harness trust relationships, enforce least privilege and human approvals, pin and validate external components, independently monitor runtime behavior, and assign governance and incident-response ownership for agentic AI.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Benjamin Kapner, Carmel Soceanu, Alicia Petrunin, and Hofni Gartner submitted a study analyzing 3,171 public GitHub repositories containing AI coding-agent configurations. The study found confirmed security defects in 16.0% of setups, including unpinned MCP servers and overly broad execution pre-approvals, and released its scanner, corpus manifest, adjudication prompt, and verdicts.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcescworld.com
Open sourcearxiv.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.