Security Research · Jul 1, 2026 · Vitalii Rudnykh

A Clean Repo, a Helpful Agent, a Reverse Shell

A GitHub repo with zero malicious code can talk an AI coding agent into opening a reverse shell — a fake setup error, a DNS TXT record, a base64 payload. Here's how the indirection chain works and how runtime interception stops it.

A Clean Repo, a Helpful Agent, a Reverse Shell