Analysis· 6 min read
AI Coding Agent Skills: The New Supply Chain Risk (2026)
AI coding agent skills execute almost anything they read. 2026 research from Koi Security, Cyata, OX Security and arXiv shows what is already in the wild.
Tag
2 posts tagged cursor.
AI coding agent skills execute almost anything they read. 2026 research from Koi Security, Cyata, OX Security and arXiv shows what is already in the wild.
SymJack hijacks symlinks inside AI coding agents to install malicious MCP servers and steal developer credentials. Here is how the attack works and what to do about it.