Innovation Hub

Get all our Latest Research & Insights
Explore our glossary to get clear, practical definitions of the terms shaping AI security, governance, and risk management.

Videos
July 22, 2026
Coding Agents, Hooks & Harnesses: Securing the Next Generation of AI Agents
The biggest security risk in a coding agent usually isn't the model - it's the harness around it. HiddenLayer researchers Kieran Evans, Kenneth Yeung, and Kasimir Schulz walk through why the layers wrapping an agent (Claude Code, Cursor, Codex, and the tools, skills, and orchestration around them) have become the real attack surface - and why, in many modern agents, you no longer need a prompt injection at all. If your instructions land in a path the model already trusts, it just follows them.
HiddenLayer Webinar: Operationalizing AI Governance: Managing Risk in Autonomous AI Systems
HiddenLayer Webinar: 2026 AI Threat Landscape Report
HiddenLayer Webinar: Offensive and Defensive Security for Agentic AI
HiddenLayer Webinar: How to Build Secure AI Agents
Report and Guides
HiddenLayer AI Security Research Advisory
_READ_ONLY_COMMANDS_POSIX expansion adds 31 commands with no path checking, granting unconditional access to the full host filesystem
Mistral Vibe automatically approves a large set of commands that are not subject to the expected workspace path restrictions, allowing files anywhere on the host to be accessed without user approval.
Environment variable prefixes stripped from permission check enable RCE via env injection
Mistral Vibe does not consider environment variable assignments when checking whether a command can run without approval, allowing environment controlled behavior in allowlisted programs such as Git to be abused for arbitrary code execution.
.avif)
In the News

Stay Ahead of AI Security Risks
Get research-driven insights, emerging threat analysis, and practical guidance on securing AI systems—delivered to your inbox.
Thanks for your message!
We will reach back to you as soon as possible.























