An AI coding assistant deleted a repo’s input-sanitization pattern while “fixing” it, and days later an autonomous red agent found the resulting injection and walked out with Jira API tokens. The lesson isn’t “AI writes bad code” — it’s that AI-authored commits are landing inside CI/CD trust boundaries that were designed assuming a human wrote the diff.

Read the Wiz writeup for the full kill chain; the HN discussion has the usual fight over whether to blame the tool or the pipeline.

The wider reaction is landing cautionary rather than panicked. The Register frames it as a systemic AI-on-AI pattern surfaced by a sanctioned red-team test, not evidence that autofix is broken, while Cyber Kendra leans harder on the irony of a fix tool shipping the vulnerability and argues teams should treat AI-generated workflow commits as untrusted code. Both land in the same place: the review bar for machine-written diffs should go up, not down — and in most pipelines right now, it’s drifting the other way.

tags: [ agentic-ai ] [ llm-ops ] [ industry ]