AI coding agents have evolved into extensible runtimes where skills, plugins, hooks, and MCP servers can reshape what they read, execute, and disclose. Security teams must govern the agent supply chain itself, because approved tools like Claude Code, OpenAI Codex, Claude Cowork, and GitHub Copilot can hide dangerous third-party capabilities behind trusted interfaces. #ClaudeCode #OpenAICodex #ClaudeCowork #GitHubCopilot #Hookify #MCPoison #Akto
Keypoints
- AI coding assistants now act as agent runtimes, not just code suggestion tools.
- Skills, plugins, hooks, and MCP servers can alter agent behavior and data access.
- Security risk has shifted from the application to the agentβs effective authority.
- Researchers have found malicious Skills, fake MCP servers, and repository-based attacks.
- Teams should inventory, control, review, and monitor the full agent extension layer.
Read More: https://thehackernews.com/expert-insights/2026/08/shadow-ai-is-now-hiding-inside.html