The Hacker News reported September 18, 2026 that Air Security documented Plugin4Shell, a SHA-pinning bypass affecting Claude Code, Codex, GitHub Copilot, and Gemini CLI. Swati Khandelwal's coverage said Anthropic patched Claude Code in 2.1.179, OpenAI patched Codex in 0.146.0, that Copilot had no fix per Air as of that report, and that Google will not patch the deprecated Gemini CLI and instead points users to migrate to Antigravity. GitHub rejects 40-hex branch names, so default GitHub marketplace plugins are not exposed to the branch-name trick, while Bitbucket and self-hosted setups can allow it. Gemini CLI has a separate FETCH_HEAD mechanism. Claude Code and Codex default to background auto-update, creating a zero-click path if a malicious update lands. The issue was found in May 2026 and disclosed in June; as of September 18 there was no CVE and no known real-world attack per The Hacker News. Help Net Security's Sinisa Markovic framed Plugin4Shell as the first supply-chain vulnerability of the AI agent ecosystem, noting plugins inherit employee reach, citing prior SkillJacking research on 925 skills across about 134,000 agents, and a fake-plugin test that reached more than 26,000 agents. Marketplace fixes alone cannot close the hole; agent updates are required. Those are unfinished patch-rollout facts plus unfinished Copilot and Gemini CLI exposure facts. They are not proof AI coding agents are already safe forever, and they are not proof every install is already owned forever.
That is an unfinished disclosure layered on unfinished vendor patch coverage. It is not a finished forever agents-safe certificate, and it is not a finished forever every-install-owned certificate.
## What They Reported
The Hacker News framed Plugin4Shell as a SHA-pinning bypass on major AI coding agents. Named vendor status said Anthropic shipped Claude Code 2.1.179, OpenAI shipped Codex 0.146.0, Copilot remained unfixed per Air, and Google will not patch deprecated Gemini CLI while urging migration to Antigravity. Platform detail said GitHub's rejection of 40-hex branch names blocks the branch-name trick for default marketplace plugins, while Bitbucket and self-hosted environments remain more open, and Gemini CLI uses a separate FETCH_HEAD path. Zero-click risk was tied to background auto-update defaults in Claude Code and Codex. Timeline detail said discovery in May 2026, disclosure in June, no CVE as of September 18, and no known real-world attack. Help Net Security called it the first supply-chain vulnerability of the AI agent ecosystem, stressed that plugins inherit employee reach, and cited SkillJacking prior art plus a fake-plugin test that reached more than 26,000 agents. Air Security and Help Net Security both stressed that marketplace policy alone is not enough and that agent updates are required. Named journalism published unfinished patch status and unfinished Copilot and Gemini CLI exposure. It did not publish that AI coding agents were already safe forever or that every install was already owned forever.
Security feeds often compress "first AI-agent supply-chain vuln" into "every install already owned forever," or compress Anthropic and OpenAI patches into "AI coding agents already safe forever." Both habits flatten what The Hacker News, Help Net Security, and Air Security published: unfinished vendor remediation and unfinished Copilot and Gemini CLI exposure, not finished forever safety and not finished forever total ownership.
## The Correction
Three corrections are required at once.
First, treating Anthropic's Claude Code 2.1.179 patch and OpenAI's Codex 0.146.0 patch as proof AI coding agents are already safe forever invents finished forever safety from unfinished rollout. Two vendors shipping fixes is a real unfinished remediation signal. It is still not AI coding agents already safe forever while Copilot remains unfixed per Air, while Gemini CLI is deprecated without a patch, and while Bitbucket and self-hosted paths remain more exposed than GitHub marketplace defaults.
Second, treating Plugin4Shell, zero-click auto-update defaults, SkillJacking scale, and a fake-plugin test that reached more than 26,000 agents as proof every install is already owned forever invents finished forever compromise from unfinished research and unfinished disclosure. The Hacker News reported no known real-world attack as of September 18 and no CVE yet. Unfinished research severity is not already every install owned forever, and unfinished research severity is not already AI coding agents safe forever.
Third, treating GitHub's 40-hex branch-name rejection, Gemini CLI's separate FETCH_HEAD mechanism, marketplace-cannot-fix-alone guidance, and May-to-June find-and-disclose timing as proof either that agents are already safe forever or that every install is already owned forever invents finished end-states from unfinished platform differences. Platform mitigations and migration advice are real unfinished hygiene work. Neither converts partial patches into finished forever safety, and neither converts a disclosed bypass without known exploitation into finished forever ownership of every install.
Accurate language therefore holds three layers apart. Layer one: September 18, 2026 The Hacker News, Help Net Security, and Air Security reported Plugin4Shell as a SHA-pinning bypass across Claude Code, Codex, GitHub Copilot, and Gemini CLI. Layer two: Claude Code 2.1.179 and Codex 0.146.0 patched; Copilot no fix per Air; Google will not patch deprecated Gemini CLI and points to Antigravity; GitHub rejects 40-hex branch names for default marketplace plugins; Bitbucket and self-hosted allow more risk; Gemini CLI FETCH_HEAD path; zero-click via auto-update defaults; found May 2026, disclosed June; no CVE and no known real-world attack as of September 18; SkillJacking prior and fake-plugin reach cited; marketplace cannot fix alone. Layer three: unfinished patch rollout plus unfinished Copilot and Gemini CLI exposure is not already AI coding agents safe forever and not already every install owned forever.
## Why This Matters
AI-agent security headlines overreact because "first supply-chain vuln" and "zero-click" travel faster than the difference between unfinished patch rollout and finished forever safety, and faster than the difference between unfinished research disclosure and finished forever ownership of every install.
False already-safe claims confuse developers into skipping version checks, migration off deprecated Gemini CLI, and scrutiny of Bitbucket or self-hosted plugin pins. False already-every-install-owned claims erase the no-known-attack reporting window and convert unfinished research into finished mass-compromise theater. Accurate coverage can report a real SHA-pinning bypass and unfinished Copilot and Gemini CLI exposure without inventing finished forever safety or finished forever ownership.
NewsCorrections technology rule: unfinished patch rollout and unfinished Copilot and Gemini CLI exposure are not already AI coding agents safe forever and not already every install owned forever.
## Key Takeaways
- September 18, 2026: The Hacker News (Swati Khandelwal), Help Net Security (Sinisa Markovic), and Air Security reported Plugin4Shell, a SHA-pinning bypass on Claude Code, Codex, GitHub Copilot, and Gemini CLI. - Patch status: Anthropic Claude Code 2.1.179 and OpenAI Codex 0.146.0 fixed; Copilot no fix per Air; Google will not patch deprecated Gemini CLI and points users to Antigravity. - Scope: GitHub rejects 40-hex branch names for default marketplace plugins; Bitbucket/self-hosted more open; Gemini CLI FETCH_HEAD path; zero-click via auto-update defaults; found May, disclosed June; no CVE and no known real-world attack as of September 18; SkillJacking prior and fake-plugin reach cited. - Unfinished patch rollout plus unfinished Copilot and Gemini CLI exposure is not already AI coding agents safe forever and not already every install owned forever. - Follow vendor versions, Copilot and Gemini CLI status, and install hygiene - not already-safe-agent or already-every-install-owned memes.


