AI · 94 days ago
AI coding agents can turn trusted telemetry into execution. If the agent can read issue trackers or observability output and then take action, poisoned error data stops being inert text and becomes a path onto the developer machine.
Tenet Security describes ‘agentjacking’ against Sentry: malicious commands are injected into error events and returned through the Sentry MCP flow in a format that looks like normal remediation guidance. The report says the technique worked across more than 100 real-world targets, with 2,388 organizations exposed to valid injectable DSNs and an 85% success rate across popular agents including Claude Code, Cursor, and Codex.
2 sources covering this story
Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code
Researchers warn Agentjacking can abuse Sentry errors to make AI coding agents run malicious code on developer machines.
New “Agentjacking” Attacks Could Hijack AI Coding Agents
Tenet Security researchers reveal how new “agentjacking” attacks could trick coding agents into executing arbitrary code
Part of the PlainSec briefing for 2026-06-13