The command allowlist was empty. The agent still ran code.
A payments firm ran an IDE coding agent in auto-run with a tight terminal allowlist, signed off by AppSec as the safe developer setup. When a bypass in this class of agent resurfaced we reproduced it in their own config: shell built-ins walk under the allowlist, poison an environment variable, and an approved git command runs attacker code. No incident. We found it first.
Read the write-up →