AI coding plugins are becoming a new part of our software supply chain.
This is a dev post classified by Jev as Security (news), kept by the Dev Radar because it carries real work, not commentary.
AI coding plugins are becoming a new part of our software supply chain. And this week we got a pretty spectacular demonstration of why that matters. 😬 Security researchers disclosed #Plugin4Shell, a vulnerability affecting several major AI coding agents. The interesting part to me isn't just the vulnerability. It's what WE can DO about it. (Spoiler: it's AppSec) If your coding agent can run plugins or skills, treat them like dependencies: → Keep your coding agent updated → Be selective about what you install → Inventory your plugins and skills → Limit what the agent can access → Keep pro
Posted by Tanya Janca | Shehackspurple (50.3k followers) 1 days ago · 7 likes · 1.3k views · view the original post on X. Kept by the Dev Radar as Security. Tools mentioned: Nutrient.
More dev work like this
- Installing agent skills from GitHub shouldn’t mean skipping a safety check. — @DanKornas
- ICYMI: The Agentic SOC is getting some backup. — @splunk
- NEAR Co-Founder. LLM co-inventor. @ekang426 husband. — @NEARProtocol
- Your AI agent can run commands. It should not get a free pass. — @DanKornas
- Digital forensics investigations can stall in the handoffs. This repo keeps the evidence… — @DanKornas
- Pentest is not a workflow, It is a search problem. — @0x0SojalSec
- ‼️Security researcher MSNightmare has released a Windows Defender update Denial of… — @DarkWebInformer
- deGDID: Deletes all instances of Microsoft's GDID and prevents minting of new ones — @DarkWebInformer
Every post is read and classified by Jev (TypeSafe): what it is, which market it belongs to, and whether the link is a real tool. 16.1k posts from 4.9k X accounts over the last 21 days, 1.8k tools, 12 markets. Collected every 5 minutes, fully re-ranked every hour — last update 2026-09-20 19:24 UTC. Full method.