AI Coding Agents Expose Zero-Click Flaw A newly discovered vulnerability dubbed Plugin4Shell allows attackers to execute remote code with a single click or none at all in AI coding agents, according to the report. The zero-click flaw grants attackers access to sensitive data and assets, highlighting the need for updated security measures to prevent supply-chain attacks. A newly discovered vulnerability, dubbed Plugin4Shell, allows attackers to execute remote code with just a single click - or none at all - giving them carte blanche access to sensitive data and assets. This zero-click flaw in AI coding agents highlights the urgent need for updated security measures to prevent devastating supply-chain attacks.