Report by Straiker
The Year Agents Entered the Workforce
6 FINDINGSPublished Jul 14, 2026
View Original Report →Key Findings
More than 1,700 successful exploits occured across production coding, productivity, and first-party AI agents during adversarial testing.
AI SecurityExploitsAgentic ThreatsOffensive SecurityAdversarial Testing
36% of successful attacks on coding agents reached remote code execution on the developer's machine.
Coding AgentsRemote Code ExecutionDeveloper SecurityOffensive Security
91% of successful attacks on productivity agents ended in silent data exfiltration.
Data ExfiltrationAI AgentsProductivity AgentsOffensive Security
Nearly a quarter (24%) of 17,651+ tracked Model Context Protocol (MCP) servers carry at least one vulnerability.
Supply ChainServer VulnerabilitiesMCP
28.6% of 130,667 cataloged tools are classified as high risk.
Tooling RiskSupply ChainAI Tools
Roughly 5% of published Skills in one marketplace were malicious or high risk.
Prompt InjectionAgent Skills