Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Sentry MCP Agentjacking 2026: How a Public DSN…
Breach analysis Incident: 12 Jun 2026

Sentry MCP Agentjacking 2026: How a Public DSN and a Fake Error Report Hijacked AI Coding Agents

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 10 min read
Category: AI agents NHI
On this page

In June 2026, Tenet Security's Threat Labs showed that anyone holding a company's public Sentry DSN could plant a fake error report that AI coding agents would later run as instructions. The DSN is a write-only credential that Sentry documents as safe to embed in website JavaScript. The attack, which Tenet calls "Agentjacking", needs nothing else. When a developer asks Claude Code, Cursor or Codex to fix unresolved Sentry issues, the agent reads the planted report through the Sentry MCP server and runs the attacker's command with the developer's own privileges. In a controlled campaign, Tenet says agents at more than 100 organisations executed its benign test package, and environments within reach held AWS keys, GitHub tokens and other credentials. No real attacker has been reported using the technique.

Key takeaways

  • The entry point is a public credential. A Sentry DSN lets anyone post error events to a project, and Sentry intends it to sit in frontend code. Tenet found 2,388 organisations with injectable DSNs through passive reconnaissance.
  • The injected event carries markdown that renders like Sentry's own guidance, including a fake "Resolution" section with an npx command. Agents querying Sentry through MCP treated it as trusted tool output and ran it.
  • Tenet reports more than 100 confirmed executions across separate organisations and an 85% success rate in its test waves, including a developer at a Fortune 100 company. These are the vendor's own figures, as The New Stack notes.
  • Agentjacking is a disclosed research technique, not a confirmed breach. Tenet's payload only probed for credentials and reported back. Sentry added a content filter for the test payload string but called the underlying issue "technically not defensible" at ingestion.
  • The identity lesson: an AI coding agent inherits every credential in the developer's environment, so any data source the agent reads can become a path to those credentials.

At a glance

OrganisationsSentry (error monitoring and its MCP server); users of Claude Code, Cursor and OpenAI Codex connected to Sentry; 2,388 organisations with exposed DSNs, according to Tenet
WhenReported to Sentry 3 June 2026; research public by 12 June 2026; updated with campaign results 17 June 2026
AttackerNone known. Found and demonstrated by Tenet Security's Threat Labs in a controlled, self-identifying test campaign
Entry pointA crafted error event posted to Sentry's ingest endpoint with a public DSN, later returned to an AI coding agent through the Sentry MCP server
Identities abusedThe public Sentry DSN (write-only by design); the AI coding agent acting with the developer's privileges; credentials in the developer's environment such as AWS keys, GitHub OAuth tokens, npm and Docker credentials and SSH agent sockets
ImpactPotential code execution on developer machines and CI agents and theft of any credential they hold; no real-world exploitation reported
CategoryAgentic AI and AI agents, NHI. Incident class: AI-agent incident (real coding agents at more than 100 organisations ran a researcher's test package)

What happened

Sentry is an error-monitoring service that applications report crashes to. Each project has a DSN, a credential the application uses to send events. Sentry documents the DSN as safe to embed in frontend JavaScript because it can only write events, not read project data. Developers increasingly connect AI coding agents to Sentry through the Model Context Protocol (MCP), so they can ask an agent to look at unresolved issues and fix them.

Tenet Security's researchers combined those two facts. Using only a public DSN, found in a site's JavaScript, through Censys or through GitHub code search, they posted crafted error events to Sentry's ingest endpoint. Sentry accepted them like any real crash. The events contained markdown that, when returned by the Sentry MCP server, rendered as headings, code blocks and a fake "## Resolution" section matching Sentry's own template. The "resolution" told the agent to run an npx command.

When a developer asked an agent to fix the Sentry issues, the agent pulled the planted event and ran the command. In Tenet's campaign the command installed a Tenet-controlled npm package that identified itself as a security scan. It checked for environment variables and files such as ~/.aws/config, ~/.npmrc and ~/.docker/config.json and reported back to a Tenet beacon server. Tenet says no credential values were kept. It reports that more than 100 agents at separate organisations executed the package. They included Claude Code, Cursor and Codex, running on macOS, Windows, WSL, cloud containers and a network-restricted CI pipeline. Tenet also says the agents still ran the payload when system prompts and skills told them to ignore untrusted data.

Tenet reported the issue to Sentry on 3 June 2026. According to Tenet, Sentry acknowledged it the same day but declined to fix it at the root, calling it "technically not defensible". During the research period it activated a global content filter blocking the specific payload string. The New Stack points out that Tenet sells an agent-runtime defence and that its figures "are best read as their own controlled test results rather than independent measurements".

Timeline

DateEvent
2 June 2026Tenet captures a current Claude Code build executing its test payload.
3 June 2026Tenet discloses the chain to Sentry, which responds the same day.
12 June 2026Cloud Security Alliance publishes a research note on Tenet's Agentjacking findings.
17 June 2026Tenet updates its research with results from more than 100 agents, including a Fortune 100 company.
21 June 2026The New Stack publishes an analysis of the attack and of Tenet's figures.

How it happened: the identity attack path

  1. A public, write-only credential. The Sentry DSN is meant to be public, and it lets anyone write events into a project. That was harmless while only humans read the events.
  2. Untrusted data inside a trusted tool. The Sentry MCP server returned attacker-written event content to the agent as tool output, formatted like Sentry's own guidance.
  3. An agent that cannot separate data from instructions. Asked to fix issues, the agent treated the planted "resolution" as a step to perform and ran the command without the developer approving it.
  4. The developer's identity, inherited. The command ran with the developer's full privileges, in an environment holding AWS keys, GitHub OAuth tokens, git and npm credentials and SSH agent access.
  5. Every step authorised. Tenet notes that nothing in the chain breaks a rule that EDR, IAM, a WAF or a firewall would flag: a valid DSN, a normal MCP query, and a command run by an approved agent.

Impact

  • Exposure: 2,388 organisations with injectable DSNs, 71 of them in the Tranco top one million sites, according to Tenet.
  • Demonstrated reach: more than 100 confirmed agent executions of a benign test package in Tenet's controlled campaign, across organisations ranging from a Fortune 100 company to individual developers.
  • Potential impact: code execution on developer machines and CI runners, and theft of cloud keys, repository tokens, package-publishing tokens and SSH access.
  • Confirmed harm: none reported. The technique has not been reported in use by real attackers.

What this means for NHI and AI agent security

Agentjacking is on our list because it turns the AI coding agent into the easiest route to a developer's non-human identities. The agent runs with whatever is in the environment: cloud keys, tokens, publishing credentials and SSH access. Anyone who can put text in front of it can try to spend that access. A public DSN, designed in good faith as a low-risk credential, becomes a remote control once an agent reads the data it writes.

The pattern is not specific to Sentry. Any MCP integration that returns data outsiders can influence, such as tickets, logs, alerts, issues or chat messages, carries the same risk. The OWASP Top 10 for Agentic Applications covers it under agent goal hijack, tool misuse and unexpected code execution. It is the same lesson as EchoLeak and ForcedLeak, now on the developer's machine rather than in a SaaS tenant.

Because the model cannot reliably tell instructions from data, the controls that work are identity controls around the agent. Keep long-lived secrets out of agent environments. Give agents short-lived, narrowly scoped credentials. Require approval before an agent runs commands that came from external data.

Recommendations

  • Keep long-lived secrets out of agent environments. Do not leave static cloud keys and tokens in environment variables or dotfiles where coding agents run. Use short-lived credentials issued per task. See our AI Coding Agents Security Guide.
  • Gate command execution. Require human approval before an agent runs package installs or shell commands, especially when the suggestion came from tool output.
  • Treat MCP tool output as untrusted. Inventory which MCP servers return externally influenced data, and restrict what an agent may do after reading it. See our MCP Security Guide.
  • Review "public" credentials. Know which of your credentials are designed to be public, such as DSNs and client-side keys, and what an attacker can write with them.
  • Scope CI agent credentials tightly. Tenet reached a network-restricted CI agent through the data it read. CI agents need the smallest token set that does the job. See our CI/CD Pipeline Identity Security Guide.
  • Rotate if exposed. If agents in your organisation ran unexpected npx commands while triaging Sentry issues, treat the credentials in those environments as exposed. Use our Leaked Credential Response Playbook.

Frequently asked questions

What is Agentjacking?

Agentjacking is Tenet Security's name for an attack where a fake Sentry error report, posted using a public DSN, carries instructions that an AI coding agent later runs when a developer asks it to fix Sentry issues. The agent executes the attacker's command with the developer's privileges.

Was Agentjacking used by real attackers?

No real-world attacks have been reported. Tenet demonstrated the technique in a controlled campaign using a benign, self-identifying test package, and says it reached agents at more than 100 organisations.

Has Sentry fixed it?

According to Tenet, Sentry blocked the specific test payload string but called the underlying issue "technically not defensible" at the ingestion layer, because it cannot tell malicious event text from legitimate error content. Protection therefore depends on how agents and their users handle tool output.

Amazon Q MCP configuration vulnerability 2026 · EchoLeak 2025 · PocketOS database deletion 2026 · MCP Security Guide · Guide to the Secret Sprawl Challenge

How NHI Mgmt Group can help

Securing Non-Human Identities (NHIs), including AI agents, is becoming increasingly crucial as coding agents run with the keys and tokens of the developers who use them. Our NHI Foundation Level Training Course gives teams the practical grounding to scope and protect those credentials.

References

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org