Free tools Windows power users keep installed
One-click scans. No signup required.
AI coding agents are not automatically safe or unsafe: risk depends on what they can read, change, execute, and reach over the network—and whether untrusted project content can influence those actions. Public reports document a Claude Code approval-bypass flaw and a Gemini CLI headless workspace-trust flaw; OpenAI documents sandbox and approval controls for Codex. Those different kinds of evidence do not establish which product is safest.
What the documented evidence says about each agent
| Product | Documented security issue or control | Important boundary |
|---|---|---|
| Claude Code | Anthropic’s August 1, 2025 advisory describes a command-parsing error that could bypass the confirmation prompt for an untrusted command. The advisory gives the issue a CVSS score of 8.7 and identifies versions below 1.0.20 as affected, with 1.0.20 as the patched version. A separate Anthropic advisory describes arbitrary code execution involving maliciously configured Git email. | The command-bypass advisory says reliable exploitation required untrusted content in Claude Code’s context. Anthropic also documents configurable filesystem and network boundaries, but those controls do not make attacks impossible. |
| Gemini CLI | A Cloud Security Alliance note dated April 30, 2026 reports that a Google advisory dated April 24 described a CVSS 10.0 remote-code-execution flaw in Gemini CLI versions before 0.39.1 and the google-github-actions/run-gemini-cli action before 0.1.22. |
The reported failure involved automatic workspace trust and loading .gemini/ configuration in headless, non-interactive CI. The CSA note is the available account of the finding here; consult Google’s primary advisory for authoritative remediation details. |
| OpenAI Codex | OpenAI documents default local sandboxing on macOS, Linux, and Windows, with edits scoped to the active workspace and network access disabled by default. Users can approve unsandboxed commands or enable network access. | These are configurable controls, not evidence that Codex has no security flaws. OpenAI warns that network access can increase prompt-injection, credential-leak, and license risks. |
The Claude version numbers and Gemini version numbers above belong to specific advisories, not a statement about every current release channel. Check the vendor’s current security notice and the exact installed version before making an upgrade decision. Anthropic’s 2025 advisory said standard auto-update users received the Claude fix and that versions before 1.0.24 had been deprecated and forced to update at that time; that historical statement should not be treated as a guarantee about all later releases.
Why prompt injection can become an execution flaw
Prompt injection describes hostile or manipulative instructions embedded in content an agent processes, such as repository files, issues, pull requests, or tool responses. The text alone does not determine the outcome. Risk rises when the agent has authority to act on that content—such as running commands, changing files, using credentials, or making network requests—and the workflow lacks an effective boundary or approval step.
The Claude Code advisory is an example of an implementation flaw in command parsing that could defeat a confirmation prompt; it is not merely a case of a model being persuaded by a bad instruction. The Gemini CLI issue reported by CSA likewise centered on a software trust decision in a headless environment, where repository-provided configuration could be loaded after the workspace was automatically trusted. In CI, a permission prompt that requires an interactive user may not be present at all.
#1 Best Overall
OpenAI’s GPT-5.3-Codex system card describes default sandboxing and warns that enabling internet access can introduce prompt injection, leaked credentials, or code with license restrictions. Anthropic’s sandbox guidance describes configurable filesystem and network boundaries; its cloud implementation keeps sensitive Git credentials outside the session sandbox and routes Git operations through a proxy that validates credentials, branch names, and repository destinations. Those are vendor-described safeguards, not independent proof that attacks cannot succeed.
How to evaluate an agent deployment
Product names alone are not a security assessment. Compare the actual configuration and workflow along these dimensions:
Rank #2
- Execution boundary: Check which files the agent can read or edit, whether it can run host commands, and what approval or escape paths permit work outside the sandbox.
- Network reach: Establish whether access is off, broadly enabled, or limited by allowlists and proxy rules. Consider whether the agent can send data to untrusted hosts or fetch hostile content.
- Untrusted input: Identify whether repository files, pull requests, issues, MCP responses, hooks, or external tools can supply instructions or configuration to the agent.
- Approval behavior: Distinguish interactive confirmation from automatic approval and headless execution. Determine who can change those settings.
- CI trust: Check whether a fork or untrusted pull request can populate a workspace used by a privileged runner, and whether project configuration is loaded before trust is established.
- Patch status: Match the installed version and action version against the exact vendor advisory. A finding against an older version does not by itself establish that a current build is affected.
This is a comparison framework, not a product ranking: the cited material covers different products, versions, and kinds of evidence, and does not provide a controlled three-product benchmark. A 2026 paper on tool-poisoning attacks in MCP clients also identifies validation, parameter visibility, injection detection, warnings, sandboxing, and audit logging as useful security dimensions; it does not establish a comparative safety score for these three coding agents.
Practical safeguards for developers and CI maintainers
Limit the authority of jobs that process untrusted code
- Do not give an agent broad host access, production credentials, or secrets it does not need for the task.
- Keep untrusted pull-request content away from privileged CI jobs unless the workflow isolates the content, execution environment, and credentials.
- Review whether the runner can alter protected branches, publish releases, or reach deployment systems; remove those capabilities from jobs that only need to analyze a change.
Review headless behavior separately
Test the CI path, not just an interactive developer session. Verify when the agent trusts the workspace, whether repository-supplied configuration is loaded, and whether approval settings require a user who will not be present in a headless job. For the Gemini CLI report, use Google’s primary advisory to confirm the fixed versions and workflow-specific remediation before changing a pipeline.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Constrain network and integrations
- Leave network access disabled when the task does not require it; otherwise, restrict destinations where the product and environment allow.
- Treat MCP servers, hooks, auto-approval, full-access modes, and external tools as changes to the trust boundary. Document what each can access and who may configure it.
- Keep credentials out of the agent’s reach where possible, and avoid exposing secrets to content that may contain hostile instructions.
OpenAI’s operational guidance describes managed configuration, approval policies, credential handling, and agent-aware telemetry as parts of its own deployment practices. Organizations adopting such controls should verify their own configuration and logging behavior rather than assume a documented vendor practice is enabled in every environment.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the findings do—and do not—show
The documented Claude and Gemini scores—8.7 and 10.0 respectively—are issue-specific CVSS severity scores, not estimates of how likely a user is to be attacked. They cannot be used to rank the products. The available material establishes neither a comparable flaw-prevalence rate across Claude Code, Gemini CLI, and Codex nor that every current version of any of them is vulnerable. The separate Claude Git-email advisory confirms a security issue, but its affected and fixed versions are not specified here, so no version-specific remediation should be inferred from it.
Quick Recap
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

