About this talk
This talk explores a critical new attack surface in command-line interface (CLI) AI agents, presented by Aonan Guan and Zhengyu Liu. The speakers analyze systemic flaws found in popular coding agents like Gemini CLI, Claude Code, and Codex, highlighting issues such as command injection, workspace escapes, and cross-process remote code executions (RCEs). They demonstrate real exploits, which have been responsibly fixed, and provide insights for developing safer, sandboxed, and verifiable AI agents.
More from this event
See all 91 talks →
BSidesSF 2026 - Opening Remarks (Sunday) (Reed Loden)
14:36
BSidesSF 2026 - Follow the data to learn the secret (Dylan Ayrey)
35:17
BSidesSF 2026 - "Ask the EFF" Panel (Panel)
45:30
BSidesSF 2026 - The Room Where It Happens (Identity Compromise Edition):... (Julie Agnes Sparks)
20:59