ReadyCIO
Menu

Note

Your AI coding tool is part of your supply chain

The tool that writes your code also installs code: plugins, extensions, servers. In September 2026 a flaw in four major coding agents showed that a pinned plugin wasn't really pinned. What that means for anyone coding with AI inside a company, and four checks that cover it.

For AI-coders September 24, 2026 securityengineering practice

Most people coding with AI think of the tool as the thing that writes code. It’s also a thing that installs code. Plugins, extensions, MCP servers: each one is someone else’s software running with your permissions, on the machine that holds your keys. In September 2026 that stopped being a theoretical point.

What happened

On September 17, 2026, AIR Security disclosed Plugin4Shell, a zero-click flaw in the plugin installers of the four best-known coding agents: Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI.

Plugin marketplaces protect you by pinning each plugin to one reviewed version, identified by its commit hash. The agents fetched by that hash but didn’t check that the code they got was the code the hash named. A plugin’s owner could create a branch named like the pinned hash, and the agent would install the branch while the pin appeared honoured. No click, no approval, no reinstall.

Anthropic fixed Claude Code in version 2.1.179, and OpenAI fixed Codex in 0.146.0. According to the researchers, Microsoft hadn’t shipped a fix for Copilot, and Google had deprecated Gemini CLI and wouldn’t patch it. GitHub pointed out that its own hosting blocks branch names that look like commit hashes. The researchers replied that Copilot can install plugins from other hosts, and that the check has to live in the agent.

Why it matters more than one bug

The attacker here isn’t a stranger. It’s whoever controls a plugin’s repository after you reviewed it. That’s the shape of most supply-chain trouble: something you trusted changes underneath you.

Small teams already accept this for their app’s dependencies and scan for it. The coding tool usually sits outside that net. Nobody records which agent and which version each person runs, who added which plugin, or where they’d hear that one had a problem.

Four checks

1. Know your tools and versions. A list: which AI coding tools the team uses, and what version each person is on. Add it to the bill of materials you already keep for the app, the one the continuous security pass builds on every run.

2. Own every plugin. Each plugin or MCP server gets a name next to it, the person who added it, and a reason. If nobody can give the reason, remove it. Fewer plugins means fewer people who can change what runs on your machine.

3. Know where advisories arrive. For each tool, the changelog or security feed you’d hear it on.

4. Put it on the schedule. The same rule as the rest of your security work: a pass that runs whether or not anyone remembers. Monthly is fine. “When someone thinks of it” isn’t.

The general lesson

“Pinned” is a claim until something verifies it. That’s true of a plugin, a package lockfile or a Docker tag. When you rely on a pin, know what checks it. Here, from the researchers’ private report in June 2026 to the fixes, nothing did.