What problem does it solve?
Tests AI IDEs for code execution vulnerabilities beyond MCP and terminal filters. Use when assessing hooks abuse, binary planting, IDE settings exploitation, tools definition auto-loading, or environment variable prefixing attack vectors. Patterns are ordered by interaction tier: Tier 1 (zero-interaction) through Tier 4 (trusted workspace + specific action).
Core Features & Use Cases
- Broad vector coverage across hooks abuse, binary planting, IDE settings abuse, tools auto-loading, environment variable prefixing, and safe-executable-with-malicious-config vectors.
- Tiered testing guidance from Tier 1 to Tier 4 for multiple IDE families (VS Code, JetBrains, CLI-based agents, and cloud agents).
- Use cases include security assessments of AI IDEs, reproducing exploit chains, and documenting mitigations for development workflows.
Quick Start
Run a comprehensive assessment of code-execution vectors in AI IDEs, from zero-click to trusted-workspace scenarios, and report actionable findings.