
Attackers are crafting malicious AI instruction files to turn your agentic workflows into quiet criminal helpers
AI agents are increasingly being deployed across the enterprise, a rapid adoption that has significantly broadened the organization’s attack surface, turning sharable AI agent resources and configuration files into backdoors, security experts warn.
AI-assisted software developers have been increasingly targeted through malicious IDE extensions, rogue MCP servers, and poisoned AI skills, all of which provide attackers inroads into organizations’ development pipelines and beyond. But these AI helper resources are not the only types of instruction files that developers and users share with one another when making use of AI coding assistants and command-line interface (CLI) agents.
For example, ...