What the agentjacking technique establishes institutionally is that the security perimeter for AI-assisted development has moved — and most teams have not moved with it. The vulnerability is not in the model weights or the training data; it lives in the trust chain between the agent and its environment. When Claude or Cursor fetches a bug report from Sentry and processes its contents, the agent treats that content as instruction. A crafted report that embeds a shell command gets the same processing pass as a legitimate stack trace .
This pattern reflects a broader dynamic flagged by analysts watching