Unveiling Command Execution Risks in AI Code CLIs: Grok Build and Claude Code
The Calculator popup that proves a point
The best security demos do something small and undeniable. A Mac Calculator app springing open at the wrong moment is exactly that — and it's what Slow Mist founder Yu Xian used to walk through a real attack surface in Claude Code and Grok Build CLI (research via ChainCatcher). The point isn't the Calculator. The point is what it represents: a config file your project already trusts, parsing into arbitrary command execution, with no prompt, no warning, no consent.
This is what a poisoning attack looks like at the end of a research chain. And the chain is short.
This is an excerpt. Read the full post at otf-kit.dev/blog/command-execution-risks-ai-code-clis — full-stack kits your AI coding agent can actually ship to production. Browse the kits →
Ship the product, not the setup.
- 11 production screens — auth, billing, team, analytics, settings
- Real database, payments, and login — all wired on day 1
- AI configs pre-tuned so your agent extends instead of regenerates