BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Bypass Lets AI Agents Run Dangerous Shell Commands

GuardFall shell trick bypasses AI coding agent safety, posing severe data and credential risks.

  • A decades-old shell scripting trick, named GuardFall, can bypass the safety checks of most AI coding agents, exposing systems to severe risks.
  • Researchers from Adversa AI found the flaw works against ten of eleven popular open-source coding agents tested, with only Continue providing robust defense.
  • The vulnerability allows hidden commands to run with full user account access, potentially wiping files or stealing SSH keys and cloud credentials.
  • Quick mitigation steps include running agents in isolated directories and disabling auto-execute flags until proper guards are implemented.

Researchers revealed in June 2026 that a simple shell trick can bypass the critical safety guardrails of popular AI coding assistants. The flaw, which exploits how bash interprets commands, was documented by security firm Adversa AI and named GuardFall.

- Advertisement -

Most agents check commands as plain text, but bash rewrites that text before execution. Consequently, a filter watching for ‘rm’ sees nothing wrong with ‘r”m’, as bash removes the quotes and runs the dangerous command anyway.

The same idea works with commands hidden in base64 or using ordinary tools like find with destructive flags. However, the researchers call this “a dangerous convention and a class of problems,” meaning no single patch can fix it.

For an attack to succeed, the AI must first produce a malicious command hidden within normal-looking work. Meanwhile, the agent must also be running autonomously with auto-execute enabled, a common setup in automated pipelines.

The vulnerability was tested against tools including opencode, Goose, and Cline, which collectively had roughly 548,000 GitHub stars. An end-to-end attack was demonstrated against the production Plandex binary, and the same method worked against eight others, as detailed in Hermes’s own issue tracker.

- Advertisement -

Only the Continue agent effectively defended itself by parsing commands as the shell would. Its design, which checks what will actually run, held up in its default editor mode against every tested payload.

Adversa recommends several immediate actions to reduce risk. These include running agents with a throwaway home directory and disabling auto-execute flags like –auto-run unless absolutely necessary.

This finding follows other similar security flaws this year. For instance, Adversa’s own TrustFall affected several major coding agents, and a separate deny-rule bypass hit Claude Code.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Microsoft Stock Plunges 20% Amid $190B AI Spend Fears

Microsoft stock (MSFT) opened Tuesday at $368, down nearly 20% in June from a...

ARK shifts from China tech to crypto stocks

Ark Invest added significant shares of Coinbase, Circle, and Bullish across its flagship ETFs...

DTCC shifts to 24×5 clearing, dimming crypto’s edge

The Depository Trust and Clearing Corporation (DTCC), which processed roughly $3.7 quadrillion in securities...

AI Browsers Tricked into Giving Up User Logins

Security researchers at LayerX tricked AI browsers into stealing user login credentials using a...

Wall Street Raises Micron Stock Target to $2000 After Earnings

Wall Street analysts at firms like Barclays and Melius Research are aggressively raising Micron's...

Must Read

How To Buy a Handshake Domain: A Step-by-Step Guide

Handshake Domains | Benefits | Drawbacks | How To Buy | Supported BrowsersIn this step-by-step guide, I am going to show you how to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading