Dev Radar
Support
LiveUpdated 2026-09-22 08:21 UTC

One of my favorite lessons from #Plugin4Shell has almost nothing to do with AI.

One of my favorite lessons from #Plugin4Shell has almost nothing to do with AI. **It's not enough to implement part of…

This is a dev post classified by Jev as Security (an opinion), kept by the Dev Radar because it carries real work, not commentary.

One of my favorite lessons from #Plugin4Shell has almost nothing to do with AI. **It's not enough to implement part of a security control. You need to verify the security property you're depending on.** The affected AI coding agents had a specific Git commit that a plugin was supposed to be pinned to. They asked Git to check out that commit. But they didn't verify afterward that the code they actually got WAS that commit. And I love this example because we make this kind of mistake in application security ALL THE TIME. Your framework can generate a CSRF token. Your frontend can send it.

Posted by Tanya Janca | Shehackspurple (50.3k followers) 10 h ago · 6 likes · 820 views · view the original post on X. Kept by the Dev Radar as Security. Tools mentioned: Nutrient.

More dev work like this

Every post is read and classified by Jev (TypeSafe): what it is, which market it belongs to, and whether the link is a real tool. 20.7k posts from 4.9k X accounts over the last 21 days, 2.4k tools, 12 markets. Collected every 5 minutes, fully re-ranked every hour — last update 2026-09-22 08:21 UTC. Full method.