[SIR-004] Silicon Sabotage: Defeating Indirect Prompt Injection in Autonomous AI Coding Agents
CLASSIFICATION: TLP:CLEAR Security Intelligence Report (SIR-004) SUBJECT: The Rise of Stochastic RCE via Indirect Prompt Injection DATE: May 5, 2026 INCIDENT CONTEXT: The 2026 reality of agents like Devin and OpenHands being hijacked via malicious READMEs and Calendar invites. The transition from assistive to autonomous AI has introduced a “Stochastic RCE” threat where untrusted data…







