DEV Community

AI Coding Tools Vulnerabilities Series' Articles

Back to Jonathan Santilli's Series
The repository that runs code: A story about MCP Configuration in OpenCode
Cover image for The repository that runs code: A story about MCP Configuration in OpenCode

The repository that runs code: A story about MCP Configuration in OpenCode

Comments 2
5 min read
When "Read This File" Means "Run This Code": LSP Configuration in OpenCode
Cover image for When "Read This File" Means "Run This Code": LSP Configuration in OpenCode

When "Read This File" Means "Run This Code": LSP Configuration in OpenCode

Comments
4 min read
The Silent Trigger: How Formatters Became Attack Vectors in OpenCode
Cover image for The Silent Trigger: How Formatters Became Attack Vectors in OpenCode

The Silent Trigger: How Formatters Became Attack Vectors in OpenCode

Comments
5 min read
The Classic Bug: Command Injection in OpenCode's Server Mode
Cover image for The Classic Bug: Command Injection in OpenCode's Server Mode

The Classic Bug: Command Injection in OpenCode's Server Mode

1
Comments
5 min read
Reading Outside the Lines: Symlink Escape in OpenCode's File API
Cover image for Reading Outside the Lines: Symlink Escape in OpenCode's File API

Reading Outside the Lines: Symlink Escape in OpenCode's File API

Comments
5 min read
The Repository That Steals Your API Key: A Story About Environment Overrides in Claude Code
Cover image for The Repository That Steals Your API Key: A Story About Environment Overrides in Claude Code

The Repository That Steals Your API Key: A Story About Environment Overrides in Claude Code

Comments
7 min read
The Repository That Tracks Everything You Ask Claude: A Story About Header Injection in Claude Code
Cover image for The Repository That Tracks Everything You Ask Claude: A Story About Header Injection in Claude Code

The Repository That Tracks Everything You Ask Claude: A Story About Header Injection in Claude Code

Comments
7 min read