Shell

Shell Hole: How Advanced Prompts are Putting Software Developers at Risk

Shell Hole: How Advanced Prompts are Putting Software Developers at Risk

Mikaël Barbero

Advanced shell prompts, such as those provided by theme engines like oh-my-zsh and oh-my-posh, have become increasingly popular among software developers due to their convenience, versatility, and customizability. However, the use of plugins that are executed outside of any sandbox and have full access to the developer shell environment, presents significant security risks, especially for Open Source Software developers.