{"slug": "pillar-research-says-the-ai-coding-agent-sandbox-leaks-through-trusted-files", "title": "Pillar research says the AI coding agent sandbox leaks through trusted files", "summary": "Pillar Security's research demonstrates that AI coding agents can be manipulated to bypass their sandbox through trusted files and tools, posing a security risk in CI/CD pipelines. The researchers showed sandbox-bypass techniques and prompt-injection attacks embedded in READMEs, code comments, and dependencies. OpenAI, Google, and Cursor have patched several reported flaws.", "body_md": "Pillar Security's latest research says AI coding agents can be pushed to act outside their sandbox through files and tools they were told to trust, and the operational read for anyone wiring one of these into CI/CD is straightforward: an agent invocation now behaves closer to a build runner reaching your production plane than to a chat window. DevOps.com's Jeff Burt covered the work on July 22.\n\nThe researchers demonstrated multiple sandbox-bypass techniques and a parallel class of prompt-injection attacks embedded in READMEs, code comments and dependencies, per the DevOps.com writeup. OpenAI, Google and Cursor have patched several of the reported flaws. Pillar's argument, as summarised there, is that the injection surface reaches every file the agent trusts on the way to the model's prompt, and every tool it can call on the way back.\n\nNone of this is entirely new to anyone who has already read Cyberhaven Lab's May note that adoption of AI coding agents is outpacing the security tools built to protect them. What Pillar adds is a concrete demonstration of the gap. A coding agent asked to do a legitimate job can be steered to take actions outside its supposed security boundary through content that arrives on paths the sandbox was not asked to police. Those are the same paths your CI already fetches for you: dependency manifests, README files, the code comments the model reads as context.\n\nThat surface has been named before. HalluSquatting and GhostApproval, both referenced in the DevOps.com piece, already gave teams a taxonomy for how AI-adjacent supply-chain attacks reach developers and their tools. Pillar's research is the sandbox counterpart. Same theme, one layer deeper into the runtime.\n\nTwo things fall out for anyone who owns a runner fleet. First, the agent's identity, network scope and filesystem access have to be tighter than the developer who invoked it, not looser. Second, a patched-vendor list is not a coverage statement. The writeup names fixes at OpenAI, Google and Cursor. It does not name a coverage floor, and until one exists, the working assumption for a team wiring an agent into a build is that every file the agent reads is part of the attack surface.", "url": "https://wpnews.pro/news/pillar-research-says-the-ai-coding-agent-sandbox-leaks-through-trusted-files", "canonical_source": "https://dev.to/leobaniak/pillar-research-says-the-ai-coding-agent-sandbox-leaks-through-trusted-files-23jk", "published_at": "2026-07-23 00:25:07+00:00", "updated_at": "2026-07-23 00:59:34.857579+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "ai-research", "developer-tools"], "entities": ["Pillar Security", "OpenAI", "Google", "Cursor", "DevOps.com", "Jeff Burt", "Cyberhaven Lab"], "alternates": {"html": "https://wpnews.pro/news/pillar-research-says-the-ai-coding-agent-sandbox-leaks-through-trusted-files", "markdown": "https://wpnews.pro/news/pillar-research-says-the-ai-coding-agent-sandbox-leaks-through-trusted-files.md", "text": "https://wpnews.pro/news/pillar-research-says-the-ai-coding-agent-sandbox-leaks-through-trusted-files.txt", "jsonld": "https://wpnews.pro/news/pillar-research-says-the-ai-coding-agent-sandbox-leaks-through-trusted-files.jsonld"}}