BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Bypass Lets AI Agents Run Dangerous Shell Commands

GuardFall shell trick bypasses AI coding agent safety, posing severe data and credential risks.

  • A decades-old shell scripting trick, named GuardFall, can bypass the safety checks of most AI coding agents, exposing systems to severe risks.
  • Researchers from Adversa AI found the flaw works against ten of eleven popular open-source coding agents tested, with only Continue providing robust defense.
  • The vulnerability allows hidden commands to run with full user account access, potentially wiping files or stealing SSH keys and cloud credentials.
  • Quick mitigation steps include running agents in isolated directories and disabling auto-execute flags until proper guards are implemented.

Researchers revealed in June 2026 that a simple shell trick can bypass the critical safety guardrails of popular AI coding assistants. The flaw, which exploits how bash interprets commands, was documented by security firm Adversa AI and named GuardFall.

- Advertisement -

Most agents check commands as plain text, but bash rewrites that text before execution. Consequently, a filter watching for ‘rm’ sees nothing wrong with ‘r”m’, as bash removes the quotes and runs the dangerous command anyway.

The same idea works with commands hidden in base64 or using ordinary tools like find with destructive flags. However, the researchers call this “a dangerous convention and a class of problems,” meaning no single patch can fix it.

For an attack to succeed, the AI must first produce a malicious command hidden within normal-looking work. Meanwhile, the agent must also be running autonomously with auto-execute enabled, a common setup in automated pipelines.

The vulnerability was tested against tools including opencode, Goose, and Cline, which collectively had roughly 548,000 GitHub stars. An end-to-end attack was demonstrated against the production Plandex binary, and the same method worked against eight others, as detailed in Hermes’s own issue tracker.

- Advertisement -

Only the Continue agent effectively defended itself by parsing commands as the shell would. Its design, which checks what will actually run, held up in its default editor mode against every tested payload.

Adversa recommends several immediate actions to reduce risk. These include running agents with a throwaway home directory and disabling auto-execute flags like –auto-run unless absolutely necessary.

This finding follows other similar security flaws this year. For instance, Adversa’s own TrustFall affected several major coding agents, and a separate deny-rule bypass hit Claude Code.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

CFTC short-staffed for prediction market oversight, hearing told

A House subcommittee examined how the CFTC can oversee prediction market platforms amid a...

Apple fixes Hide My Email flaw that leaked real addresses for over a year

Apple fixed a flaw in its Hide My Email service on July 3, 2026,...

White House pushes Dems to accept Trump’s crypto ethics deal

The White House is urging Senate Democrats to accept President Trump's ethics deal to...

Telegram to roll out native Gram wallet for 1B users

Telegram founder Pavel Durov announced a native non-custodial Gram wallet rolling out to all...

Augustus raises $180M for Global Dollar Bank at $1B valuation

Augustus raised $180 million in Series B funding at a $1 billion valuation, led...

Must Read

Top 5 Best Crypto Faucets To Earn Free Crypto This Year

QUICK LINKSWhat Are Crypto Faucets and How Do They Work?How Do Crypto Faucets Make Money?What to Expect: Realistic EarningsThe Best Crypto Faucets of 2025:...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading