AI Coding Agents Face Security Flaw in Skill Update Verification

Security startup AIR reported that a verification loophole has been discovered in four AI coding agents, potentially enabling automatic installation of malicious code. The firm confirmed the same design flaw in Claude Code, OpenAI Codex, Gemini CLI, and GitHub Copilot on July 17.
AIR explained that attackers could replace legitimate skill repository content with malicious code, causing the agents to apply updates without verifying fixed versions. This could lead to remote code execution without user intervention, exposing enterprise code and internal data accessible by the agents.
Anthropic has patched the issue in Claude Code 2.1.179, while OpenAI addressed it in Codex 0.146.0. Microsoft has been notified about GitHub Copilot's vulnerability but hasn't released a patch yet. AIR noted that Google discontinued Gemini CLI and migrated users to Antigravity instead of patching the flaw.
Korean Source
This article is an English localization of a Korean-language crypto news report. Original headline: AI 코딩 에이전트 4종, 스킬 업데이트 검증 허점