Researchers at AIR have described Plugin4Shell, a flaw in how four AI coding agents check that a plugin is the exact version a marketplace approved, Help Net Security reported on 18 September. The affected tools are Claude Code, Codex, GitHub Copilot and Gemini CLI. Because two of them update plugins in the background by default, the report says a plugin that passed review can be swapped for hostile code without the developer doing anything.
Background
AI coding agents run on a developer's own computer, with access to the shell, the file system and stored credentials. Plugins extend them, and marketplaces pin each plugin to a specific commit so that the code a reviewer approved is the code that runs. The flaw concerns that pin [1].
What the report describes
According to the report, the agents do not confirm that the code they check out ends up at the pinned commit. An attacker can create a branch whose name matches a commit hash, so the checkout resolves to the attacker's code while the pin still looks intact. The report notes that GitHub blocks such branch names, while Bitbucket and self-hosted servers allow them [1].
The report calls the flaw zero-click because the same checkout runs again during background auto-updates, which are the default in Claude Code and Codex. An attacker can either publish a plugin that later turns hostile or take over an existing plugin repository. AIR reported finding 925 compromised skills that reached 134,000 agents through such takeovers [1].
Patch status differs by vendor. Anthropic fixed Claude Code in version 2.1.179 and OpenAI fixed Codex in version 0.146.0. Microsoft has not released a fix for GitHub Copilot, and Google has deprecated Gemini CLI and points users to a different product, Antigravity. AIR says it found the flaw in May and disclosed it to vendors in June [1].
Implications for Mac users
The report is about developer tooling on any desktop operating system and does not single out macOS. Developers who use one of the four agents with plugins from third-party marketplaces are the exposed group. Mac users who do not use coding agents are not affected by this flaw as described [1].
Recommendations
- Update Claude Code to version 2.1.179 or later and Codex to version 0.146.0 or later.
- Turn off background plugin auto-update where the tool allows it, and update plugins deliberately.
- Remove plugins that are not in active use, and prefer plugins hosted on GitHub, where the report says the branch-name trick is blocked.
- Where GitHub Copilot or Gemini CLI is in use, treat third-party plugins as unpatched exposure until the vendor states otherwise.
Relevance to FireAI
FireAI is a network firewall for macOS. It does not vet plugins, inspect git checkouts or stop a coding agent from running a command. What it can do is show and control the connections that follow: a new process that has no rule yet triggers a prompt in Alert mode, named with its destination, and per-app rules can restrict where a given tool is allowed to connect.
Limitations
The account rests on one secondary report. It does not say whether the flaw has been exploited outside research, and it does not describe how AIR arrived at the figure of 925 compromised skills. The report does not state which operating systems were tested.
Try FireAI, by HisnLabs free for 17 days.