An AI assistant can answer questions, draft letters, read email and manage a calendar. It does not perform all of those tasks alone. It relies on plugins and other add-ons built by outside developers. One fetches web pages, another reads documents, a third files expenses, a fourth books travel. When the assistant calls one of these tools, the tool may inherit access to your files and credentials and to whatever services are connected. The assistant borrows a pair of hands, and the tool may borrow your authority.
This arrangement solves a practical problem. A general model can reason about a journey, but booking a flight requires a connection to an airline’s reservation system. Those connections are tedious to build and maintain, so developers package them as reusable tools. The result resembles an app store with a longer chain of trust. You trust the assistant, which trusts the plugin, and both rely on a security review that may have happened months earlier.
On 17 September 2026, AIR Security disclosed Plugin4Shell, a flaw affecting Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI. Plugin catalogues lock an approved add-on to one reviewed version of its code by recording that version’s fingerprint, a long string called a commit hash. The affected agents asked for the pinned version but never checked that the code they installed carried the fingerprint they asked for. An attacker who controlled a plugin’s repository could label a branch of hostile code with a name shaped like the fingerprint, and the underlying software, Git, can favour the label over the fingerprint when the two collide. The agent would then install the attacker’s code and report the approved version. In Claude Code and Codex, background updates could deliver the substitution without a fresh prompt, and the code would run with the agent’s access to files and credentials and to any connected systems.
The trick needed a code-hosting service that allows a branch to carry a fingerprint-shaped name. GitHub forbids those names. Bitbucket and some self-hosted servers permit them. Gemini CLI had a related weakness involving FETCH_HEAD, a shortcut name Git uses during downloads. Plugins drawn only from the default GitHub-hosted catalogues avoided the branch-name path, though the unverified checkout existed in the agents regardless.
A pharmacy approves a supplement after testing one batch. The batch number goes on file, and later shipments are accepted when the label carries that number. A dishonest supplier changes the contents and leaves the label alone. Plugin4Shell was the digital version of the swapped shipment. The fingerprint was on file and the delivery completed, but the agent never compared what it received with what the fingerprint named.
In NIST SP 800-53, control SR-4 covers provenance, the record of where software came from, and SI-7 covers software and information integrity, the assurance that it has not been altered. Canada’s ITSP.10.033 carries the corresponding controls as SR-04 and SI-07. The controls existed. The agents verified the version requested without confirming the code received.
The Mobius Nexus Cycle examines a form of influence that integrity checks cannot see. Its systems can pass those checks and still be steered.
The novels call it a managed basin. Rain can fall in different places and take different routes, yet the shape of the land carries every drop toward the same lake. Mathematics calls the region that drains to one outcome a basin of attraction, and the idea applies to any changing system, since the starting states inside a basin tend toward the same stable end. In a managed basin, someone has altered the landscape deliberately. Some outcomes become easier to reach and others harder, and separate minds, choosing freely at every step, converge on the result the manager prefers.
Applied to a person, the method needs no direct coercion. It changes the conditions under which choices are made. One route becomes easier or more familiar while alternatives take more effort. The person can inspect each decision and find no interference, because the influence lies in how the options were arranged over time.
Plugin4Shell changed the code while preserving the record. A managed basin preserves both the code and the record while changing the conditions around them. Every fingerprint can match and every audit can pass while an unmodified system converges on a selected outcome, because the choices presented to it have been shaped. Controls that examine artefacts can detect a substituted plugin. They are far weaker at showing why an intact system keeps moving in one direction.
That is the gap exploited in The Mobius Fragments. The accountability system of the Fragments Operation checks whether records and content remain intact, and it misses the harmonization beneath them, because the influence acts on relationships and conditions outside the inspected artefacts. The audit is accurate within its scope and blind to what is steering the system.
Plugin4Shell can be blocked where vendors shipped fixes. AIR Security reported them in Claude Code 2.1.179 and Codex 0.146.0, while GitHub Copilot had no patch at disclosure and Google did not plan one for the deprecated Gemini CLI. Updating to a fixed agent and restricting where plugins can come from reduce the immediate risk, and careful teams can also confirm the resolved code before it runs. A managed basin offers nothing comparable to replace. Its code and provenance stay clean because the influence lives in the environment where decisions are made.
RECORD RETAINED


