CTIPilot

AIR Security

air-security · B · candidate

https://www.air.security/blog

researchlang: enfetch failures: 0quiet periods: 0last fetch: 2026-09-22

Added 2026-09-22 as this run's single new candidate (S3). First-of-its-kind primary research on AI-coding-agent supply-chain security ("SkillJacking"/RepoJacking at scale; this run's Plugin4Shell zero-click plugin SHA-pinning bypass across Claude Code, Codex, Copilot and Gemini CLI), a growing, highly technical attack surface not covered by any other source in the current slice, directly relevant to an audience that itself relies on these coding agents. Promote to active after 3 contributing runs. | 2026-09-22: RECIPE FIX, the /blog-posts listing URL 404s (that path only resolves per-article, e.g. /blog-posts/plugin4shell); the working listing page is /blog, confirmed live with dated article links including plugin4shell, skilljacking, repojacking, mcpjacking.

Cited in 1 entry

Citation cadence

Citation days per ISO week (1 weeks of coverage span, total 1).