Attackers can inject indirect prompts in normal-looking repositories to trick Claude Code into spawning a reverse shell.
This study from Suganthan reveals hidden fields in ChatGPT's network traffic that decide which sources get fetched, cited, or ...