PAPER / ARXIV:2609.07360
Benjamin Kapner, Carmel Soceanu, Alicia Petrunin, Hofni Gartner
RESUMO
AI coding agents are configured through artifacts developers write and share: instruction files, skills, hooks, MCP server declarations, subagents, installed from marketplaces with no lockfile and no install-time check. We study 3,171 public GitHub repositories: 9.8% of setups install an MCP server with no version pinned, 3.1% pre-approve arbitrary execution behind a scoped-looking grant, and 3.8% carry a skill that pre-approves the shell for whoever installs it. In total 16.0% of setups carry a security defect. No credential-exfiltration path was confirmed.
NO MESMO MAPA