Malware for AI-coding agents can evade static scanners by over 90 percent through simple packing techniques, but requires complementary runtime checks for detection.
Legitimate AI agents inherently satisfy all three criteria of the “lethal trifecta” (data access, external content, external communication), so security must shift from architectural design to runtime monitoring.