Turncoat: From Coding Agent to C2 Agent
DAY 2
14:00-
14:40
Coding agents routinely execute shell commands, modify files, and apply patches based on responses from remote model APIs. This means the model endpoint is not only a source of text, but also part of the local execution trust boundary.
Turncoat is an open-source proof of concept that implements a Codex-compatible API and supplies tool calls to an unmodified coding-agent client. It demonstrates how control of an inference endpoint or gateway can be translated into control of agent actions, without first compromising the client itself.
The session presents the threat model, the design of the control server, and a live demonstration of direct and proxied tool-call injection. It also examines the limits of existing defenses such as approval prompts, sandboxing, endpoint configuration, and execution logs, and discusses practical mitigations for organizations operating coding agents through custom providers or enterprise AI gateways.
-
Location :
-
Track 3(Room 3)
-
-
Category :
-
Bluebox
-
-
Share :
Speakers
-
Michael Telloyan
マイケル・テロイヤン
Michael Telloyan is a security researcher and graduate student at the University of Tokyo. He is a CODE BLUE Bluebox speaker and has served as an instructor for Security Camp and Global Cybersecurity Camp. He was also a Google Summer of Code contributor with Mandiant.