Skip to finding
§
High
Agent harnesses
Confirmed

Untrusted remote content can become desktop-user commands inside agent harnesses.

Across 12 tested harnesses, data crossed role or scope boundaries and reappeared as higher-authority context.

Affects

Twelve coding and general-purpose agent harnesses that assemble instructions from web pages, repositories, archives, skills, subagents, and tool output

What it enables

Host command execution through automatic promotion of attacker-controlled content into privileged agent context

Attacker publishes a website, repository, archive, skill, or tool response containing instructions in a location expected to be treated as data→↓Victim asks an affected agent to process that content→↓The harness imports or rediscovers the content in a higher-trust role or broader scope than its origin→↓In the Claude Code demonstration, archive exploration dynamically discovers a nested SKILL.md and an inline action reuses an already-approved node command→↓The attacker-supplied action executes with the agent process's desktop-user privileges
Why this matters

The changed assumption is the data-versus-instruction boundary itself: every evaluated harness admitted a demonstrated form of context privilege escalation.

Detail and 2 sources
Required access

Control content that a victim asks an agent to browse, clone, extract, or inspect; some demonstrated chains also reuse a routine command approval already granted for the session

Affected versions

Codex 0.120.0, Claude Code 2.1.88, Gemini CLI 0.39.0-nightly, Qwen Code 0.14.4, Kimi CLI 1.33.0, Aider 0.86.3.dev, OpenCode 1.4.3, Cline 3.77.0, Goose 1.30.0, Pi-mono 0.67.68, OpenClaw 2026.4.12, Hermes Agent 0.9.0

Proof of concept

Demonstrated by the researcher

The attacker controls a website, repository, archive, skill or tool response that the victim asks an affected agent to process. Some chains also reuse a routine command approval already granted in the session.

In the Claude Code demonstration, exploring an archive discovered a nested SKILL.md; its inline action reused an approved Node command and executed with the agent user's privileges.

Some vendors shipped mitigations, but not all did, and the assessed capability remains present.

Evidence
The paper documents proof-of-concept attacks against all twelve evaluated harnessesThe Claude Code remote-archive chain is described node by node through host command executionThe paper reports that some, but not all, affected vendors shipped mitigations
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 3, 2026