Shadow AI Risk Moves Inside Approved AI Coding Agents

Summary
AI agent extensions and configuration can influence what tools an agent uses, what data it accesses, and where that data goes. The article explains this supply-chain risk and recommends inventorying, reviewing, and monitoring agents’ effective capabilities.
Key points
- AI coding agents can inspect repositories, edit files, run commands, access internal systems, and act with limited supervision.
- Skills, plugins, hooks, repository instructions, and MCP servers can alter an agent’s behavior and expand its access without adding a new binary.
- A single plugin may bundle multiple capabilities, creating transitive trust and authority users may not expect.
- Approving an AI application alone does not reveal the agent’s active components, permissions, connected identities, or external destinations.
- The article recommends inventorying agent configurations and capabilities, using managed registries and allowlists, and reviewing component updates.
- Organizations should monitor consequential actions and record which user, agent, component, tool, permissions, and data were involved.
- Security testing should check whether poisoned instructions or configuration can trigger unsafe actions, not just whether a model can be jailbroken.
Article Details
- Topic
- Security risks and governance of plugins, Skills, hooks, MCP servers, and other extensions in AI coding-agent supply chains
People
Products
Claude CodeThe real problem is that tools such as Claude Code, OpenAI Codex, Claude Cowork, and GitHub Copilot are becoming extensible agent runtimes. Skills, plugins, hooks, repository instructions, and MCP servers can influenceClaude CoworkThe real problem is that tools such as Claude Code, OpenAI Codex, Claude Cowork, and GitHub Copilot are becoming extensible agent runtimes. Skills, plugins, hooks, repository instructions, and MCP servers can influenceGitHub CopilotThe real problem is that tools such as Claude Code, OpenAI Codex, Claude Cowork, and GitHub Copilot are becoming extensible agent runtimes. Skills, plugins, hooks, repository instructions, and MCP servers can influenceOpenAI CodexThe real problem is that tools such as Claude Code, OpenAI Codex, Claude Cowork, and GitHub Copilot are becoming extensible agent runtimes. Skills, plugins, hooks, repository instructions, and MCP servers can influence