Opening hook
Replaces the first line of the post. Pick one, or write your own.
Artwork
Clifton Flack
Chief Commercial Officer, SLA Pharma
Four of the most-used AI coding agents trusted a pin that could lie. The pin looked intact the whole time. Last week researchers disclosed a flaw affecting four of the most widely used AI coding agents —
Claude Code, Codex, Copilot and Gemini CLI. The mechanics are worth following even if you never open a terminal. These tools let you pin a plugin to one specific, reviewed commit, so you know exactly which code you're running. The agents checked out that pinned commit — and never verified they had landed on it. A repository owner could create a branch named after the pin and serve entirely different code underneath it. Zero clicks. Nothing to approve. The pin looked intact throughout. Anthropic and OpenAI have patched. Google deprecated its CLI. No exploitation has been found in the wild. Here's the part founders should sit with. The whole pitch for an AI-first small team is that you install capability instead of hiring it. Five people, forty tools, no headcount. What nobody says out loud is that every install is a supplier — and your company has onboarded dozens of them, with write access to your code, your inbox and your customer records, with no procurement, no contract and no idea who maintains them. A larger company calls this third-party risk and gives it a department. You made each of those decisions in under a minute, between other tasks. I'm not arguing for fewer tools. I'm arguing for a list. What makes this one worth your attention is that the control everyone trusted was doing less than it appeared to. That's the shape of the risk in AI tooling right now: the safeguards feel like safeguards. Could you write down today every plugin, extension and MCP server with write access to your business, and who maintains each one? #AISecurity #SmallTeams #ThirdPartyRisk
1,811 / 3,000 · folds at ~210
Workflow
“Post to LinkedIn” goes out publicly, straight away. The draft button is the safe rehearsal.
For a post you put on LinkedIn yourself. Records it as posted here without sending anything.