Six popular AI code assistants (Amazon Q Developer, Claude Code, Augment, Cursor, Google Antigravity, Windsurf) can execute code undetected on developer systems through symlink exploits in attack scenarios known as GhostApproval.
AI agents fail to recognise trust boundaries between private and public resources, becoming an unintended bridge between sensitive internal systems and the public internet.
Prompt injection cannot be completely prevented, but can be drastically mitigated through input filtering, data separation, access restriction, and monitoring.
AI agents require dynamic identities, short-lived secrets, and gradually reduced privileges instead of static access rights to ensure security and auditability.
AI accelerates software development but simultaneously eliminates traditional security checkpoints, potentially resulting in poorly protected applications.