Analysis · curated 11 Sep 2026
AI Coding Tools - Yale Center for Research Computing
First reported yale.edu
Coverage timeline
Single-source advisory — first reported, latest, and curated coincide.
Why it matters
Coding agents act with a user's full permissions and are vulnerable to prompt injection, so this guidance highlights concrete data-exposure, credential-leak, and code-execution risks defenders must mitigate when deploying AI agents in shared computing environments.
The Yale Center for Research Computing published guidance on the security risks of AI coding agents (e.g., Claude Code) on HPC clusters, warning that such agents can expose lab data, leak credentials like SSH keys and API tokens, take unintended actions across shared environments, and execute arbitrary or malicious code. The document specifically notes that coding agents are susceptible to prompt injection attacks in which malicious instructions embedded in read content are executed by the agent.