Most coding agents run setup instructions without asking a single question
A published exploit chain shows exactly why that habit is dangerous.
A coding agent pointed at a malicious README runs pip install verbatim, against an attacker-controlled package index.
The exploit e
blog.bhuveshdhiman.com1 min read