Security researchers documented an attack called “agentjacking” where fake error reports injected via Sentry’s public credentials can turn AI coding agents into code-execution engines on developers’ machines through the Model Context Protocol. The exploit requires no malware or password theft to compromise Claude Code, Cursor, and Codex.