Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
AI Coding Tools Vulnerabilities Series' Articles
Back to Jonathan Santilli's Series
The repository that runs code: A story about MCP Configuration in OpenCode
Jonathan Santilli
Jonathan Santilli
Jonathan Santilli
Follow
Jan 21
The repository that runs code: A story about MCP Configuration in OpenCode
#
ai
#
mcp
#
opencode
#
devsec
Comments
2
comments
5 min read
When "Read This File" Means "Run This Code": LSP Configuration in OpenCode
Jonathan Santilli
Jonathan Santilli
Jonathan Santilli
Follow
Jan 22
When "Read This File" Means "Run This Code": LSP Configuration in OpenCode
#
opencode
#
ai
#
lsp
#
devsec
Comments
Add Comment
4 min read
The Silent Trigger: How Formatters Became Attack Vectors in OpenCode
Jonathan Santilli
Jonathan Santilli
Jonathan Santilli
Follow
Jan 23
The Silent Trigger: How Formatters Became Attack Vectors in OpenCode
#
opencode
#
ai
#
formatters
#
devsec
Comments
Add Comment
5 min read
The Classic Bug: Command Injection in OpenCode's Server Mode
Jonathan Santilli
Jonathan Santilli
Jonathan Santilli
Follow
Jan 25
The Classic Bug: Command Injection in OpenCode's Server Mode
#
api
#
backend
#
cybersecurity
#
security
1
reaction
Comments
Add Comment
5 min read
Reading Outside the Lines: Symlink Escape in OpenCode's File API
Jonathan Santilli
Jonathan Santilli
Jonathan Santilli
Follow
Jan 28
Reading Outside the Lines: Symlink Escape in OpenCode's File API
#
opencode
#
ai
#
devsec
#
agents
Comments
Add Comment
5 min read
The Repository That Steals Your API Key: A Story About Environment Overrides in Claude Code
Jonathan Santilli
Jonathan Santilli
Jonathan Santilli
Follow
Jan 30
The Repository That Steals Your API Key: A Story About Environment Overrides in Claude Code
#
claudecode
#
ai
#
vulnerability
#
devsec
Comments
Add Comment
7 min read
The Repository That Tracks Everything You Ask Claude: A Story About Header Injection in Claude Code
Jonathan Santilli
Jonathan Santilli
Jonathan Santilli
Follow
Feb 4
The Repository That Tracks Everything You Ask Claude: A Story About Header Injection in Claude Code
#
claudecode
#
anthropic
#
ai
#
devsec
Comments
Add Comment
7 min read
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account