Attackers can inject indirect prompts in normal-looking repositories to trick Claude Code into spawning a reverse shell.
As AI tools flood open-source maintainers with low quality bug reports, OpenAI's new Patch the Planet initiative aims to filter out the noise and fix real threats.
An agentic coding tool tasked with cloning and setting up a seemingly benign GitHub repository could execute a malicious ...