Summary
Security firm Tenet Security has disclosed “agentjacking,” a novel attack class that enables threat actors to hijack AI coding agents — including Anthropic’s Claude Code and Cursor — by injecting malicious instructions through Sentry, the widely-used error-tracking platform. In controlled testing across over 100 organizations, the attack achieved an 85% success rate.
The technique exploits a fundamental weakness in how AI coding agents process external data. Attackers inject carefully crafted instructions into fake error reports using publicly available Sentry Data Source Names (DSNs). When an AI agent queries Sentry for unresolved errors, it interprets the injected payloads as legitimate diagnostic steps and executes attacker-controlled code with the developer’s full privileges. Successful exploitation can expose environment variables, Git credentials, private repository URLs, and developer identities, while also establishing persistent access.
The attack bypasses traditional security tools entirely because the actions appear authorized to the AI agent — it’s following what it believes are legitimate remediation instructions. Researchers note that the same vulnerability pattern extends beyond Sentry to other monitoring platforms like Datadog, PagerDuty, and Jira, anywhere an AI agent fetches and acts on external data.
Sources
- The Hacker News — Agentjacking Attack Tricks AI Coding Agents
- VentureBeat — The Attack That Hijacked Claude Code Came Through Sentry
- SecurityWeek — New Attack Abuses Claude Code
Commentary
This is the kind of attack that should keep every engineering org awake at night. AI coding agents are being granted sweeping permissions on developer machines — SSH keys, cloud credentials, production configs — and they fundamentally cannot distinguish between legitimate data and adversarial instructions. The confused deputy problem, but with root access.
The 85% success rate is staggering, and the attack surface extends well beyond Sentry. Any platform where an AI agent reads external data — error trackers, ticket systems, monitoring dashboards — is a potential injection point. Until AI agents develop robust instruction/data boundary enforcement, organizations need to sandbox these tools aggressively and audit what external sources they can query.
