
Open security research on AI coding agent infrastructure. Agent-executable remediation manifests for CVE-2026-22812 and CVE-2026-22813.
Open security research on AI coding agent infrastructure.
Published by Hodge Luke Digital Intelligence Agency
This repository contains security research, vulnerability analysis, and remediation guidance for AI coding agent platforms. Every advisory includes an agent-executable remediation manifest — a structured document your AI coding agent can read and execute directly.
Most security advisories tell you what's wrong and what to do. You still have to do it yourself.
Our advisories ship with a remediation manifest — a structured set of instructions with STOP_IF conditions, ASK_USER directives for credentials, and REPORT checkpoints. Copy the manifest. Paste it into your AI coding agent's chat. Say: "Do this."
The agent reads the manifest, executes each step in order, stops when a condition isn't met, and asks you for credentials only when it needs them. It does not guess. It does not skip.
This is how security advisories should work in 2026.
Quick start: Open advisories/CVE-2026-22812-22813/remediation.md, copy the manifest, paste into your AI agent.
advisories/
CVE-2026-22812-22813/
ADVISORY.md # Technical summary
remediation.md # Agent-executable remediation manifest
exposure-data.md # Sourced exposure statistics
SOURCES.md # Full citation list
hardening/
linux-vps.md # Layer 4 hardening for Ubuntu/Debian
macos.md # Layer 4 hardening for macOS
The complete vulnerability analysis, reproduction methodology, and 5-layer defense-in-depth architecture is published as a blog post:
FORGE implements the 5-layer defense architecture described in this research as a one-command deployment. $47 once. Your VPS. Your code. No recurring fees.
See CONTRIBUTING.md for how to submit findings.
MIT — the research is free. Use it to protect your infrastructure.
Hodge Luke Digital Intelligence Agency forge.useacceda.com