Sunday 26 July 2026 16:04:02 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#GhostApproval


GhostApproval Turns AI Coding Assistants Into a File-System Trap

Published: 11 July 2026 16:32Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: INTEGRITYFOX

A trust-boundary flaw in six code agents shows how a malicious repository can manipulate sandboxed tools, not by breaking the model, but by abusing path handling and approval design.

GhostApproval Turns AI Coding Tools Into Unwitting File Writers

Published: 09 July 2026 16:33Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

A newly disclosed trust-boundary flaw shows how repository tricks can push coding assistants past their workspace limits, where a single bad write may become a serious host-level security problem.

GhostApproval Raises a Hard Question for AI Coding Tools: What Happens When Trust Is Only an Illusion?

Published: 09 July 2026 16:11Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

Wiz has disclosed GhostApproval, an attack method that uses a decades-old technique to mislead AI coding assistants and test the limits of approval-based security on developer machines.

When AI Approvals Drift: GhostApproval and the Broken Promise of Workspace Safety

Published: 09 July 2026 15:07Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: INTEGRITYFOX

A symlink-based trick shows how agentic coding tools can be pushed beyond the directory a user thinks they approved.

When an AI Editor Trusts the Wrong Path, the Workspace Stops Being Safe

Published: 09 July 2026 14:25Category: AI Security & Agentic SystemsAuthor: INTEGRITYFOX

A symlink flaw pattern called GhostApproval shows how approval prompts in AI coding tools can be fooled into sending writes beyond the intended workspace boundary.