Security research on the boundaries of AI coding agents.
Every serious AI-agent escape of 2026 had the same shape: the agent trusted something the repository supplied. Not a model bug — a boundary bug. The component that enforces the boundary runs in the environment it polices, and takes its parameters from untrusted input: a repository, an issue, a patch, a tool result.
agent-boundary-scan
(abs) — scan a repository for the places where an AI coding agent gets hijacked:
git config sinks, filter drivers, repo-declared MCP servers, agent hooks, GIT_* env
channels, devcontainer lifecycle commands, escaping symlinks. CLI, SARIF, CI gate.
pip install agent-boundary-scan abs . # text report abs . --format sarif # GitHub code scanning abs . --fail-on high # CI gate
mcp-surface-scan
(mss) — read an MCP client config and report what each declared server can reach
before you mount it: launch-time package resolution, remote endpoints, credentials in
env, host-reaching container flags, path arguments that mean "everything".
A write-up covering twelve coding agents — reproducing each vendor's git hardening exactly and measuring which execution sinks still fire — is under coordinated disclosure and will appear here once the vendors have responded.
Agent boundary review — one scope: where does the thing that enforces the boundary take its parameters from? Git sink coverage, approval-parser differentials, MCP and configuration surfaces.
Vendor-side boundary reviews (git sink coverage, approval-parser differentials, MCP and config surfaces) and team training on using coding agents safely: open an issue on the repo, or reach out — first contact costs nothing.