
Your Agent Allowlist Says Python. It Means Any Command.
A scan of 3,171 public repositories found 16.0% of AI coding-agent setups carry a security defect. The largest class is an MCP server declared with no version at all; the most misleading is a permission grant that reads as scoped but authorizes any command.
September 10, 2026 · 13 min read