← Founder Notes
Archive

The agent ecosystem just got its first supply-chain vulnerability. air security disclosed…

Yethikrishna ROriginal on Threads

the agent ecosystem just got its first supply-chain vulnerability. air security disclosed plugin4shell on september 17, a zero-click remote code execution found in the four most popular coding agents through their plugin systems, affecting millions of installs.

the plugin store is the new npm.

Context

Air Security's blog of 17 September 2026 describes Plugin4Shell, a SHA-pinning bypass affecting Claude Code, Codex, Copilot and Gemini CLI, zero-click through background plugin auto-update (the default in Claude Code and Codex). The Register, 17 September 2026, reports it was reported to all four vendors in June, that Anthropic patched in Claude Code 2.1.179 and OpenAI in Codex 0.146.0, that Google deprecated Gemini CLI and said it would not patch, and that Microsoft did not fix Copilot, with a GitHub spokesperson saying the attacks do not affect GitHub-hosted marketplaces because GitHub blocks branch and tag names resembling SHAs.

How it compares

The 17 September date is supported by Air, the vendor that found the flaw. The four most popular agents, millions of installs and first-of-its-kind are Air's own framing and are not independent; install counts were not inspected. The note omits the patches. Affects all four holds for the design flaw as Air describes it, not as exploitability on GitHub per GitHub's statement. The Gemini CLI deprecation wording comes from The Register and should not be read as covering every Gemini product. The plugin store is the new npm is the author's analogy.

Watch next

  • Copilot patch status and vendor advisories.

Sources

  1. Plugin4Shell (Air Security, 17 Sep 2026)air.security
  2. AI coding agents 0-click RCE flaw (The Register, 17 Sep 2026)theregister.com

Provenance

The note above is reproduced unedited from the original post, first published on Threads on 20 September 2026 at 21:20 IST. Sources are the papers and datasets the note draws on.

View the original post
Embed this note
<iframe src="https://founder.myndlabs.tech/notes/embed/the-agent-ecosystem-just-got-its-first-supply-Ddg8mMFDR0n" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="The agent ecosystem just got its first supply-chain vulnerability. air security disclosed…"></iframe>

More notes