One keypress is all it takes to compromise four AI coding tools
ID: f280734d-548a-5a58-a4f1-94dd45d99be7
STIX ID: report--f280734d-548a-5a58-a4f1-94dd45d99be7
Feed Name: Help Net Security
**TrustFall research** shows that several AI coding CLIs (Anthropic Claude Code, Google Gemini CLI, Cursor CLI, GitHub Copilot CLI) can auto-start project-defined MCP helper programs when a developer accepts a default "trust this folder" prompt, enabling immediate execution of attacker-controlled code that can read SSH keys, cloud credentials, and exfiltrate data; a headless CI variant has no prompt and can be abused via malicious pull requests. The report includes a proof-of-concept exfiltration, notes enterprise mitigation via centrally managed settings (Managed scope) to disable project-scoped MCP auto-approval, and highlights disagreement with vendor messaging about whether prompts adequately disclose execution risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
