Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Latest AI and industry news. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

News AI News

A public download counter becomes an API-key leak channel.

Novee Security's research (surfacing in trade press now) shows Claude Code, Gemini CLI, and Codex all shipped flaws that let an attacker exfiltrate.

Enterprise DNA |
A public download counter becomes an API-key leak channel.

AI Pulse · Under the Radar

The play

Audit agent tools for public telemetry and shared-workspace leaks, then confirm vendors’ patches before allowing secrets into automated workflows.

A security finding now surfacing in the trade press is a useful reminder that AI coding tools can leak data in places nobody thinks to inspect. Researchers at Novee Security found flaws in Claude Code, Gemini CLI and Codex that each created a path for instructions or secrets to cross boundaries they should not cross.

In Claude Code, the issue involved Hugging Face’s public download counter. An attacker could use that innocent-looking telemetry signal as a covert channel, sending secret data out one character at a time from inside the sandbox. The affected range covered releases 0.2.54 through 2.1.162. Gemini CLI could be hit through a crafted .gemini/.env file that enabled operating system command injection. In Codex, a shared job checkout could allow one job to plant instructions that the next job would blindly load. All three vendors have patched the reported flaws, according to the trade press report.

The bigger business lesson is not that these three tools are uniquely unsafe. It’s that public telemetry, shared workspaces and configuration files can become side channels when an AI agent has access to code, credentials or production-adjacent systems. If your team is using coding agents, treat their environment like any other automated worker. Limit what secrets they can read, separate jobs and repositories, review configuration files, and keep versions current.

This is the kind of thing we build into an AI command centre, where agent activity, access and exceptions can be made visible before a small technical shortcut becomes a security incident.

Working With Claude field guide cover

Free Resource

Put what you just read to work

The free 32-page Working With Claude guide: the full ecosystem, Claude Code, and how to roll it out across a business.

No spam. Unsubscribe any time.

Free daily email

Get this every morning.

This brief is one item from today's AI Pulse, the short daily read we run for ourselves on what is actually happening in AI. Subscribe free and it lands in your inbox each morning.

Free daily email

Subscribe to the daily AI Pulse

One short read every morning on what is actually happening in AI. Free.

One email a day. Unsubscribe any time.