AI coding agents can turn trusted telemetry into execution. If the agent can read issue trackers or observability output and then take action, poisoned error data stops being inert text and becomes a path onto the developer machine.
Tenet Security describes ‘agentjacking’ against Sentry: malicious commands are injected into error events and returned through the Sentry MCP flow in a format that looks like normal remediation guidance. The report says the technique worked across more than 100 real-world targets, with 2,388 organizations exposed to valid injectable DSNs and an 85% success rate across popular agents including Claude Code, Cursor, and Codex.