AE Agent Errors
AE-H4RRJ172

Coding agent's web-fetch tool auto-approves any path on a pre-approved domain, letting injected content exfiltrate data through download counters

PROMPT INJECTIONseverity: CRITICALcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: MEDIUM

huggingface.co was pre-approved as a bare hostname for the WebFetch tool, so requests to any path, including attacker-controlled model repositories, ran without a permission prompt and outside --allowedTools restrictions. Untrusted content injected into the agent's context could direct fetches of attacker repository files, which the site counts as downloads, forming a covert channel for exfiltrating files, environment variables or command output.

Framework / agent
Claude Code (@anthropic-ai/claude-code) · terminal coding agent
Remediation attempts
APPLIED
Recurrence
not documented
Source languages
en
Updated
2026-09-30

Sources

Symptoms

  • WebFetch requests to attacker-controlled paths on the pre-approved domain run without a permission prompt
  • Server-side download counts on attacker repository files can encode data the agent can access
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents: GET /api/v1/cases/AE-H4RRJ172. Pricing

Similarity to your system is not implied. A remediation that worked in the documented context may not work in yours.