ai-ide-code-exec

Evaluate code-execution vectors in AI IDEs across VS Code, JetBrains, CLI, and cloud agents.

61|8|Updated Feb 16, 2026
One-click install
npx skills add https://github.com/Mindgard/ai-ide-skills --skill ai-ide-code-exec
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ai-ide-code-exec
Source: https://github.com/Mindgard/ai-ide-skills/tree/main/skills/ai-ide-code-exec
Command: npx skills add https://github.com/Mindgard/ai-ide-skills --skill ai-ide-code-exec

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Tests AI IDEs for code execution vulnerabilities beyond MCP and terminal filters. Use when assessing hooks abuse, binary planting, IDE settings exploitation, tools definition auto-loading, or environment variable prefixing attack vectors. Patterns are ordered by interaction tier: Tier 1 (zero-interaction) through Tier 4 (trusted workspace + specific action).

Core Features & Use Cases

  • Broad vector coverage across hooks abuse, binary planting, IDE settings abuse, tools auto-loading, environment variable prefixing, and safe-executable-with-malicious-config vectors.
  • Tiered testing guidance from Tier 1 to Tier 4 for multiple IDE families (VS Code, JetBrains, CLI-based agents, and cloud agents).
  • Use cases include security assessments of AI IDEs, reproducing exploit chains, and documenting mitigations for development workflows.

Quick Start

Run a comprehensive assessment of code-execution vectors in AI IDEs, from zero-click to trusted-workspace scenarios, and report actionable findings.

Frequently Asked Questions about ai-ide-code-exec

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I test AI IDEs for code execution vulnerabilities beyond MCP and terminal filters?

To test AI IDE code execution vulnerabilities, identify and evaluate vectors like hooks abuse, binary planting, IDE settings exploitation, and tools auto-loading across major IDE families using tiered interaction patterns.

What attack vectors are used for AI IDE code execution exploitation?

AI IDE code execution attack vectors include hooks abuse, binary planting, IDE settings exploitation, tools definition auto-loading, environment variable prefixing, and safe-executable-with-malicious-config scenarios.

How do I assess zero-click to trusted-workspace code execution risks in VS Code and JetBrains?

Assess code execution risks in VS Code and JetBrains by applying tiered testing guidance from Tier 1 zero-interaction to Tier 4 trusted-workspace scenarios, analyzing workspace file influence and trust prompts.

How can I detect TOCTOU risks and scope escapes in AI IDE executable paths?

Detect TOCTOU risks and scope escapes by analyzing executable-path resolution, workspace file influence, trust prompts, and per-IDE configurations to identify reproducible exploit chains and scope boundary violations.

Does this AI IDE security testing cover CLI-based agents and cloud agents?

Yes, AI IDE security testing covers CLI-based agents and cloud agents alongside VS Code and JetBrains, evaluating code-execution vectors across all major IDE families using standardized tiered interaction patterns.

What are the limitations of testing environment variable prefixing and binary planting vectors in AI IDEs?

Limitations include varying per-IDE configurations and trust prompt behaviors that affect binary planting and environment variable prefixing detection, requiring analysis of executable-path resolution and safe-executable-with-malicious-config scenarios.