Four September 2026 CVEs in Codex CLI, Roo-Code, OpenClaw and Ollama came from approval gates that read commands differently from the shell. Ollama fixed its version by deleting the prefix parser, and gates that match exact strings and refuse unmodeled syntax close that gap by design.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives30
- Confidence50
Anthropic's docs say Claude Code mods run in their own sandbox, yet can read your files, start processes and make network requests. That sandbox only routes access through one $ API, so the trust decision happens at install.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Claude Code 2.1.285's Read deny rules let 4 of 11 file-reading routes reach the model in a developer's test, among them grep -r and CLAUDE.md @imports. The docs limit the rules to named paths and point anyone needing a hard block to the OS sandbox.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives30
- Confidence60
One SCP deny line blocked an AdministratorAccess session in a scratch AWS account, according to a dev.to guide to sandboxing coding agents. Its three gaps, the management account, service-linked roles and outside principals admitted by resource policies, set where an agent can run.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence40
Four core SAP build packages shipped an identical 11.6MB credential stealer. Because npm trusted the whole cap-js repository rather than one branch, a commit pushed to an unused branch was enough to publish them.
Publishers:stepsecurity.io
Reality
- Evidence60
- Adoption38
- Hype gap+15
- Incentives78
- Confidence55
AgentGate read the shipped code behind 30-plus OSV and GHSA flags, verified 19 npm packages as malicious, and found 18 still resolvable on publication day. Removal, not detection, is where the chain stopped.
Reality
- Evidence48
- Adoption20
- Hype gap+22
- Incentives78
- Confidence55
Datadog Security Labs put one document-portal prompt through three coding agents in both modes and audited all six builds. An insecure direct object reference appeared in each, and one build per cell leaves mode effects entangled with noise.
Publishers:securitylabs.datadoghq.com
Reality
- Evidence52
- Adoption
- Insufficient
- Hype gap+12
- Incentives68
- Confidence45
Novee Security's Black Hat findings land the same lesson on three agents: a validator that inspects a cleaned-up copy of a command is not a control, and a sandbox built too late is not one either.
Reality
- Evidence42
- Adoption55
- Hype gap+27
- Incentives68
- Confidence45
Check Point found Claude Code project configs could execute commands and steal Anthropic API keys on clone. Anthropic has patched it. The trust model it exposed is still yours to manage.
Publishers:research.checkpoint.com
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+15
- Incentives65
- Confidence60
A dev.to writeup makes a point worth stealing: the secret leaves your machine in a prompt, not a commit. The proposed fix is a local proxy that masks values before egress.
Reality
- Evidence32
- Adoption
- Insufficient
- Hype gap+12
- Incentives72
- Confidence40
CVE-2026-22708 let injected text rewrite a Cursor agent's environment, so an approved "git branch" ran something else. It worked with an empty allowlist too.
Reality
- Evidence58
- Adoption45
- Hype gap+18
- Incentives78
- Confidence55
A Mac utility replaces plaintext credentials with fake ones and injects the real value into an approved process after Touch ID. The pattern is now on every security team's evaluation list.
Reality
- Evidence36
- Adoption9
- Hype gap+28
- Incentives68
- Confidence38