Analysis · curated 15 Aug 2026

Coding Agent Security: Lessons from Claude Code, Cowork, Codex, and Copilot in the Wild

Coverage timeline

15 Aug 2026substack.com 1 Sep 2026medium.comaurascape.ai 10 Sep 2026akto.io

Why it matters

Coding agents combine file access, untrusted inputs, and command execution, making them prime targets for indirect prompt injection that can lead to arbitrary code execution and data exfiltration on developer machines, so defenders need agent-specific controls.

A lessons-learned analysis of coding-agent security draws on real-world incidents and vulnerabilities in Claude Code, Cowork, Codex, GitHub Copilot, and Amazon Q Developer, tying them to Simon Willison's 'lethal trifecta' (private data, untrusted content, external communication) and documented indirect prompt-injection-to-RCE flaws such as the Amazon Q find/-exec bypass and CVE-2025-53773 in Copilot. The piece synthesizes prevention strategies for restricting agent permissions and hardening against external manipulation.