Plugin4Shell SHA Pins Fail as Codex Copilot Auto and Actions Tighten Trust

At a glance

  • Air Security's Plugin4Shell shows major coding agents checkout a marketplace-pinned SHA but never verify HEAD, so a 40-hex branch name can swap in malicious plugin code.
  • Codex CLI v0.155.0 adds experimental `/voice` and Touch ID gates for MCP on supported Macs. Pin v0.155.1 for the safer reasoning-summary default.
  • Copilot Auto adds Efficiency, Balance, and Intelligence tiers that steer cost versus quality without leaving Auto.
  • GitHub Actions workflow execution protections are GA, with a public-repo default that disables `pull_request_target` (enforce Nov 2, 2026).

Sunday is a security and control morning more than a fresh ship day, so the useful work is how these four moves tighten trust boundaries around agents. Marketplace SHA pins were the industry answer to plugin rug-pulls, and Plugin4Shell shows that guarantee fails inside the agent unless you update. Codex still ships local UX (voice and biometric MCP consent) while Copilot gives quota-pressed teams an Auto tier dial, and Actions finally hardens who and what can start workflows that agent PRs often trip.

Treat today as a pin-and-patch, voice-opt-in, Auto-tier, and Actions-policy day. Confirm Claude Code is past v2.1.179 and Codex past v0.146.0 (prefer v0.155.1), decide whether Copilot marketplaces on non-GitHub hosts are in scope, pick an Auto tier for everyday work, and put `pull_request_target` policies into evaluate mode before Nov 2.

Top Stories

Plugin4Shell: marketplace SHA pins fail inside major coding agents Practical dev impact: Air Security (Sep 17) and follow-on coverage describe Plugin4Shell as a client-side SHA-pinning bypass: Claude Code, Codex, GitHub Copilot, and Gemini CLI clone and checkout the marketplace-pinned commit but do not assert that `HEAD` equals the pin afterward. Git can prefer a branch whose name is the same 40-hex string over the commit object (`refname is ambiguous`), so an attacker who controls the plugin repo can make checkout land on malicious tree content while the pin still looks honored. Background plugin auto-update (default on Claude Code and Codex for built-in marketplaces, per Air) turns a later pin bump into a zero-click path. Air attributes fixes to Claude Code v2.1.179+ and Codex v0.146.0+. Gemini CLI will not be patched (deprecated; migrate to Antigravity). GitHub told The Register it blocks SHA-shaped branch and tag names on github.com, so the branch-name variant does not work on GitHub-hosted plugins, while Air notes Bitbucket and self-hosted marketplace backends remain in scope and says Copilot still lacked an agent-side fix as of disclosure coverage. Inventory marketplace hosts, pin agents past the fixed lines, and treat “we pinned the SHA” as incomplete until the client verifies `rev-parse HEAD`.

Codex CLI v0.155: experimental /voice and Touch ID for MCP Practical dev impact: OpenAI published Codex v0.155.0 on Sep 17 with experimental `/voice` conversations (live transcripts and mic controls, enabled via `/experimental`), live TUI reasoning summaries plus completion timestamps, task hide/archive/delete and worktree cleanup, Touch ID verification for MCP requests in local TUI on supported Macs, configurable daemon updates, and Bedrock credentials-from-command support. The same-line bug fixes harden WSL sandbox escapes and MCP OAuth expiry reporting. Follow-up v0.155.1 (Sep 18) leaves reasoning summaries disabled by default for new local TUI sessions so providers that reject them stop breaking turns, while explicit reasoning-summary settings still apply. Pin to v0.155.1 if you want voice and biometric MCP gates without inheriting the v0.155.0 summary default, then opt into `/voice` only on machines where mic access is acceptable.

Copilot Auto tiers: Efficiency, Balance, and Intelligence Practical dev impact: GitHub Changelog (Sep 14, recirculated in the Sep 18 weekly) adds three Auto selection tiers that share the same model pool and still evaluate each prompt. Efficiency favors cost and speed for straightforward work, Balance weighs cost, quality, and latency for everyday coding, and Intelligence prioritizes quality for harder tasks, while a simple docstring edit can still land on a small model even on Intelligence. The rollout covers VS Code, Copilot CLI, and the GitHub Copilot app. Billing follows the model Auto picks, and paid subscribers keep the 10% Auto discount. After Friday’s mid-October deprecation list, pick a default tier for your team so quota burn is a deliberate dial rather than whatever Auto happened to choose last week.

Actions workflow execution protections go generally available Practical dev impact: GitHub Changelog (Sep 17) moves workflow execution protections to GA for Enterprise, orgs, and repositories. Actor allowlists control who can trigger a workflow and event rules control which events may start it, evaluated before a run. GA adds per-workflow-file targeting, Insights for evaluate-versus-enforce auditing, and a REST API so you can manage protections as code. For public repos without an applicable event policy, GitHub introduces a default that disables `pull_request_target` (evaluate mode first), with automatic enforcement on November 2, 2026 for repos still on that default. That trigger runs with base-repo secrets and is a common Pwn Request / fork-secrets class, which matters more as agents open PRs from forks and branches. Run Insights in evaluate mode this week, then either keep the block or explicitly allow `pull_request_target` only for the workflows that still need it.

Practical Impact Analysis

Today’s through-line is trust boundaries around agents: plugins, tools, models, and CI triggers. Plugin4Shell shows that marketplace review plus a pinned SHA is not enough if the agent never checks that checkout landed on that commit, so fleet pins and marketplace-host policy become the real controls. Codex v0.155 then raises a different trust surface (mic and MCP consent) while Copilot Auto tiers give you a cost and quality policy without hard-coding model ids that mid-October will churn anyway. Actions execution protections close the loop for agent-heavy repos where a clever PR event should not be enough to run privileged workflows.

If your org installs plugins from any marketplace, Sunday is the day to confirm Claude Code and Codex versions, list non-GitHub marketplace backends, and decide whether Copilot plugin installs stay allowed until Microsoft ships an agent-side fix. If you run Codex locally on Macs, treat Touch ID for MCP as a rollout checkbox and keep `/voice` experimental until policy says otherwise. Platform owners should set a default Auto tier beside the Oct 19 model migration checklist from yesterday, then put Actions execution protections into evaluate mode and clear `pull_request_target` debt before Nov 2.

If you only do three things this morning: verify agent versions against Plugin4Shell fixed lines and marketplace hosts, pin Codex to v0.155.1 and choose a Copilot Auto tier, and open Actions Insights for `pull_request_target` before the November enforce date.

Tutorial

Verify Claude Code and Codex pins, then assert HEAD matches a checkout SHA. Use a throwaway clone so you do not touch production plugins. Keep secrets in the environment.

1. Confirm Claude Code is at least v2.1.179 (weekend fleets may already be on v2.1.278+) and Codex is at least v0.146.0 (prefer v0.155.1). 2. In a temp repo, create a commit, check it out by SHA, and assert `git rev-parse HEAD` equals the pin. 3. Next ops steps (manual): list marketplace hosts (GitHub versus Bitbucket or self-hosted), decide Copilot plugin policy until an agent-side fix ships, set a Copilot Auto tier, and open Actions Insights for `pull_request_target` before 2026-11-02.

bash Tutorial
claude --version
# Expect at least 2.1.179; weekend pins at 2.1.278+ are fine.

npm install -g "@openai/codex@0.155.1" 2>/dev/null || true
codex --version

WORKDIR="$(mktemp -d /tmp/pin-assert.XXXXXX)"
cd "$WORKDIR"
git init -q
git config user.email "dev@example.com"
git config user.name "dev"
echo ok > README.md
git add README.md
git commit -qm "seed"
PIN="$(git rev-parse HEAD)"

... click "Show full code" below to expand
▸ Show full code (18 lines)
claude --version
# Expect at least 2.1.179; weekend pins at 2.1.278+ are fine.

npm install -g "@openai/codex@0.155.1" 2>/dev/null || true
codex --version

WORKDIR="$(mktemp -d /tmp/pin-assert.XXXXXX)"
cd "$WORKDIR"
git init -q
git config user.email "dev@example.com"
git config user.name "dev"
echo ok > README.md
git add README.md
git commit -qm "seed"
PIN="$(git rev-parse HEAD)"
git checkout -q "$PIN"
test "$(git rev-parse HEAD)" = "$PIN" || { echo "PIN MISMATCH"; exit 1; }
echo "HEAD matches pin: $PIN"

Recommended AI prompt

Copy this paragraph into ChatGPT, Claude, Gemini, Grok, or whatever you use.

You are my staff engineer for coding-agent supply-chain hygiene, Codex CLI rollout, Copilot Auto policy, and GitHub Actions trigger hardening on 2026-09-20. Plugin4Shell is a SHA-pinning bypass where Claude Code, Codex, Copilot, and Gemini CLI checkout a marketplace-pinned commit but do not verify HEAD equals the pin; patches are attributed to Claude Code v2.1.179+ and Codex v0.146.0+; Gemini CLI is unpatched and deprecated. Codex v0.155.0 adds experimental `/voice` and Touch ID for MCP; pin v0.155.1 for the safer reasoning-summary default. Copilot Auto adds Efficiency, Balance, and Intelligence tiers. Actions workflow execution protections are GA, with a public-repo default that disables `pull_request_target` (enforce Nov 2, 2026). Ask which agents, marketplace hosts, Copilot surfaces, and public Actions repos we run. Then produce a Plugin4Shell version and marketplace-host checklist, a Codex v0.155.1 enablement note for voice and Touch ID MCP, a recommended Auto tier policy tied to quota, and an Actions evaluate-to-enforce plan for `pull_request_target` before Nov 2. Keep it concrete and copy-paste ready.

Recommended AI prompt

Explore each Top Story in Grok. Links open in a new tab. On phones, the same link may open the Grok app if you have it installed (via your device's normal link handling).

Article: Plugin4Shell SHA Pins Fail as Codex Copilot Auto and Actions Tighten Trust

Privacy: links open grok.com in your session only. AIDevPulse does not run your prompts through our API.

Leave a Comment