GovKM
Provenance at Use Time in AI Plugin Supply Chains

The Hash Was Right. The Code Was Wrong.

Plugin4Shell showed that a valid pinned commit record can coexist with execution of different code. Provenance must be revalidated at the moment of use.
Governance illustration representing a plugin marketplace with a valid pinned commit record while the coding agent executes different attacker-controlled code.
Expand image

A record of provenance is not provenance if the runtime no longer points to the recorded object.

AIR Security disclosed Plugin4Shell, a SHA-pinning bypass affecting several major AI coding agents. A marketplace could review and record a known-good plugin commit while the agent later resolved and executed different attacker-controlled code. Vendors issued fixes for affected products, with patch status varying by product at disclosure.

The continuity failure

The institution preserved the approved commit record while losing continuity between that record and the code actually executed.

The GovKM interpretation

Provenance must be revalidated at use time. Identifiers, hashes, repository paths, and approval records are only evidence if they continue to resolve to the same artifact.

Continuity path: Source/reviewed plugin → Evidence/pinned commit → Authority/marketplace approval → Context/agent install → Action/executed code → Record.

Source

AIR Security, “Plugin4Shell — Zero Click RCE Vulnerability Found in Top 4 Most Popular Coding Agents,” September 17, 2026.

RELATED KNOWLEDGE

Continue Exploring

Explore related research, framework domains, and continuity concepts.
CONTINUE WITH THE FRAMEWORK

Explore the continuity relationships that support trustworthy organizational intelligence.

Continue through the GovKM Framework to examine the doctrine, knowledge, and implementation guidance behind Organizational Continuity.