Glossary · Term

arbitrary code execution

← all terms

Definition

Plain language

A hole that lets an outsider run any command they want on your machine.

As stated in the literature

A vulnerability class in which an attacker can cause a target process to execute commands or code of their choosing; in agent harnesses this typically means escaping the approval layer to reach a shell.

Also called: arbitrary-code-execution, ACE, arbitrary command execution

Why it matters: Once an attacker can run any command, every other protection on that machine becomes decoration, because they can simply turn it off or read around it.

For example, a text box meant to hold a filename might instead be fed a sneaky string that makes the server run a command deleting files or downloading an attacker's program.

Heard on the show

“One pure text-based baseline, ACE, actually *inflated* execution cost up to three-point-eight times — nearly quadrupled what the agent had to spend — for a tiny accuracy bump.”
Episode 168 — When Turning Experience Into Code Makes Your AI Agent Dumber

Related terms