Agentjacking Attack Hijacks AI Coding Agents Via Sentry Errors

Researchers reveal how attackers hijack AI coding assistants through trusted error-monitoring pipelines, no phishing required.

By Central
Agentjacking exploits Sentry's MCP integration to feed malicious commands to AI agents.
Highlights
  • Attackers inject crafted error events into Sentry to hijack AI agents like Claude Code and Cursor.
  • The technique achieves an 85% success rate and already hit Fortune 500 and hosting firms.
  • Sentry called the ingestion-layer flaw 'not technically defensible' and pointed to model-side mitigations.

A novel attack technique, dubbed “Agentjacking,” is actively exploiting the trusted relationship between AI coding assistants and the widely used Sentry error-monitoring platform, enabling attackers to execute arbitrary code on developer machines using nothing more than a single fabricated error event. Researchers at Tenet Security have demonstrated that by injecting crafted error data into publicly accessible Sentry Data Source Names (DSNs), adversaries can hijack AI agents such as Claude Code and Cursor, transforming them into unwitting execution vectors for malicious commands. The attack requires no phishing, malware delivery, or direct breach of the victim’s infrastructure.

How the Agentjacking Attack Chain Works

The attack capitalizes on the architectural junction between Sentry’s event ingestion pipeline and its Model Context Protocol (MCP) integration, which feeds error data back to AI coding agents as trusted system output. Sentry’s DSN is a write-only credential routinely embedded in frontend JavaScript and indexed across the web, making it a readily discoverable entry point. Tenet’s researchers identified 2,388 organizations with injectable DSNs through passive reconnaissance methods including JavaScript inspection, Censys searches, CDN loader analysis, and code search. Among these, 71 were in the Tranco top-1M ranking of most popular websites.

With only a DSN, an attacker can submit arbitrary error events to Sentry’s ingest API, controlling fields such as messages, tags, context, extra data, breadcrumbs, user information, stack traces, and fingerprints. Sentry accepts these forged events as legitimate application errors, allowing attackers to inject fully controlled content into monitoring workflows.

Crafted Markdown Masquerades as Remediation Guidance

Attackers embed carefully crafted Markdown within injected errors, particularly in message and context fields, to influence how content is displayed to AI agents. The content can appear as a legitimate Sentry “Resolution” section with headings, code blocks, and tables, making it indistinguishable from genuine remediation guidance. When a developer asks their agent to “fix unresolved Sentry issues,” the AI queries Sentry via MCP, retrieves the crafted event, and interprets the attacker’s command as legitimate diagnostic steps rather than untrusted input.

Code Execution via Trusted Channels

Tenet’s proof-of-concept payload directed agents to execute an npx command that pulled a controlled validation package from the public npm registry and ran it with the developer’s full local privileges. In their controlled campaign, this package confirmed the presence of sensitive material by probing environment variables, checking the sizes of configuration files such as ~/.aws/config and ~/.docker/config.json, and inspecting network interfaces. The package then sent scoped exposure metadata back to a Tenet beacon server under explicit “ResponsibleDisclosure [SECURITY SCAN]” headers.

Real-World Impact and Success Rate

Tenet reports more than 100 confirmed cases of real-agent execution across a Fortune 500 cloud enterprise, a multi-billion-dollar hosting provider, scientific software firms, startups, and individual developers. The attacks achieved an overall success rate of about 85% across leading AI coding agents, affecting organizations spanning six continents.

What Makes Agentjacking Particularly Dangerous

Every step in the attack chain is authorized and appears benign to traditional defenses. Sentry is used as designed, DSNs are public by policy, the npm package is fetched over standard channels, and the AI agent executes commands as part of its normal assistance workflow. Endpoint detection, web application firewalls, IAM policies, and firewalls detect no obvious policy violations because the observable behavior matches a developer-approved tool running approved commands on a trusted observability platform. Tenet describes this as an “Authorized Intent Chain,” arguing that current security models, which focus on blocking unauthorized actions or malicious binaries, lack effective visibility into attacks that operate solely through trusted context and legitimate tool output.

A Systemic AI-Agent Vulnerability, Not a Single-Vendor Bug

The research underscores that Agentjacking is not a flaw unique to Sentry or any single AI coding agent. Any MCP integration that returns externally influenced data to agents carries a similar risk, as the data may contain hidden instructions controlled by attackers. Current AI models cannot reliably distinguish descriptive data from embedded instructions, especially when those instructions appear in seemingly trusted logs, metrics, or error messages.

Tenet disclosed its findings to Sentry on June 3, 2026. Sentry acknowledged the issue and introduced a global content filter for a specific payload string, but reportedly characterized the underlying class of attack as “not technically defensible” at the ingestion layer, instead pointing to model-side middleware as the appropriate mitigation point.

What Organizations and Developers Should Do Now

The Agentjacking work signals a new era in AI supply chain risk, where the AI agent itself becomes the primary attack surface. Security teams need to reassess which tools their AI agents interact with and whether those tools accept untrusted or anonymous input. Immediate actions include implementing runtime controls that prevent injected content from automatically translating into code execution on developer endpoints, and deploying an AI-aware security monitoring solution capable of detecting anomalous command sequences initiated by AI agents, regardless of whether individual commands are authorized. Developers should review their Sentry DSN exposure, restrict DSNs where possible, and ensure that AI coding agents are configured with the principle of least privilege, limiting the scope of commands they can execute autonomously. Adopting a policy of manual approval for any command that modifies system state or accesses sensitive data is a practical first step until AI agents can reliably distinguish descriptive data from embedded instructions.

Share This Article