Definition
A new style of attack that hides malicious instructions in the setup or configuration steps an AI coding agent runs automatically — before its safety sandbox or human-approval checks ever kick in. Because the code runs at 'startup', not during the AI's normal reasoning, standard AI guardrails never see it.
Why it matters
This defeats the safety promise organizations rely on when they let AI coding agents operate semi-autonomously, and researchers showed it works across seven major agent platforms with a single automated exploit.