Your coding agent runs a shell on your machine. I audited mine.
A developer who maintains agentproto, an open runtime that lets AI agents run commands on a user's machine, audited the tool after a teardown of opencode revealed a CVE involving a default HTTP server…