
May 20, 2026 · 12 min read
SecurityAttacking Production Apps Without Jailbreaking the Model: Scope Manipulation with scopeshift
scopeshift demonstrates that Claude Code and other AI coding agents can be tricked into running unauthorized pentests through network-layer deception alone — no adversarial prompts required. The agent thinks it's probing localhost, but the traffic lands on a real third-party target.
Eduard Agavriloae
Director R&D


















