Agent security and tool invocation
A defensive agent can become the execution path for malicious code when it reads an untrusted repository in an auto-approved mode. The reported proof of concept placed ordinary-looking project guidance and a security script inside a modified geopy repository. Claude Code and Codex inspected the files, accepted the script as safe, and ran a malicious binary. The authors report remote code execution across several Claude Code CLI versions and Codex CLI 0.142.4.
Model Context Protocol (MCP) servers show a related tool-safety problem. SpellSmith addresses taint-style attacks by adding security-aware instructions to tool descriptions and making the model reflect before final tool use. Its survey found 43 taint-style cases among 53 MCP vulnerability reports, while existing tool metadata rarely included security guidance. On 792 malicious prompts, the reported attack success rate was 0.13%.