DEV Community

Toni Antunovic profile picture

Toni Antunovic

CTO / Builder

Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to Joined on  Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
Transitive Prompt Injection in Multi-Agent Coding Pipelines: One Poisoned Tool, Every Downstream Agent

Transitive Prompt Injection in Multi-Agent Coding Pipelines: One Poisoned Tool, Every Downstream Agent

Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
9 min read

Want to connect with Toni Antunovic?

Create an account to connect with Toni Antunovic. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
Slopsquatting: The Attacker Playbook for AI-Hallucinated Package Names

Slopsquatting: The Attacker Playbook for AI-Hallucinated Package Names

1
Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
10 min read
When Every PR Is a Rubber Stamp: What Automated Gates Catch That Exhausted Reviewers Miss

When Every PR Is a Rubber Stamp: What Automated Gates Catch That Exhausted Reviewers Miss

Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
8 min read
Clinejection: When Your AI Coding Tool Became the Weapon

Clinejection: When Your AI Coding Tool Became the Weapon

1
Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
9 min read
CLAUDE.md Is a Security Boundary

CLAUDE.md Is a Security Boundary

2
Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
7 min read
What LucidShark Would Have Caught Before the TanStack Attack Landed

What LucidShark Would Have Caught Before the TanStack Attack Landed

Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
7 min read
Approve Once, Exploit Forever: The Trust Persistence Vulnerability Vendors Will Not Fix

Approve Once, Exploit Forever: The Trust Persistence Vulnerability Vendors Will Not Fix

1
Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
6 min read
How to Review Code Your AI Agent Wrote While You Were Sleeping

How to Review Code Your AI Agent Wrote While You Were Sleeping

Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
7 min read
The Georgia Tech CVE Data Shows AI Code Tools Have a Volume Problem

The Georgia Tech CVE Data Shows AI Code Tools Have a Volume Problem

1
Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
7 min read
The Co-Authored-By Copilot Controversy Misses the Real Problem

The Co-Authored-By Copilot Controversy Misses the Real Problem

1
Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
6 min read
CVE-2026-26268: How Cloning a Repo Can Now Execute Attacker Code in Your AI IDE

CVE-2026-26268: How Cloning a Repo Can Now Execute Attacker Code in Your AI IDE

10
Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
6 min read
The MCP RCE That Anthropic Won't Patch: Your Enforcement Checklist

The MCP RCE That Anthropic Won't Patch: Your Enforcement Checklist

2
Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to 1
6 min read
572K Weekly Downloads, One Preinstall Script: The SAP CAP Supply Chain Attack Your AI Agent Would Have Missed

572K Weekly Downloads, One Preinstall Script: The SAP CAP Supply Chain Attack Your AI Agent Would Have Missed

1
Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
3 min read
When Your AI Coding Tool Disappears Overnight: The Case for Provider-Agnostic Quality Gates

When Your AI Coding Tool Disappears Overnight: The Case for Provider-Agnostic Quality Gates

1
Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to 1
6 min read
AI Hallucinated Dependencies Are the New Supply Chain Attack: How to Stop Them

AI Hallucinated Dependencies Are the New Supply Chain Attack: How to Stop Them

Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
8 min read
AI Agents Generate Code That Passes Your Tests. That Is the Problem.

AI Agents Generate Code That Passes Your Tests. That Is the Problem.

9
Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to 6
6 min read
Project Glasswing Found 35 CVEs in March. Here Is the Quality Gate You Need Before AI Agents Touch Your Codebase.

Project Glasswing Found 35 CVEs in March. Here Is the Quality Gate You Need Before AI Agents Touch Your Codebase.

Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
7 min read
When a Git Branch Name Becomes a Weapon: The Codex Command Injection That Could Steal Your GitHub Token

When a Git Branch Name Becomes a Weapon: The Codex Command Injection That Could Steal Your GitHub Token

Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
6 min read
OWASP Top 10 for Agentic Applications 2026: What Every Claude Code User Needs to Know

OWASP Top 10 for Agentic Applications 2026: What Every Claude Code User Needs to Know

3
Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to 2
11 min read
When Your Security Scanner Becomes the Weapon: Lessons from the Trivy Supply Chain Attack

When Your Security Scanner Becomes the Weapon: Lessons from the Trivy Supply Chain Attack

1
Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
2 min read
npm Provenance and SLSA: The Supply Chain Hygiene Baseline Every Team Needs in 2026

npm Provenance and SLSA: The Supply Chain Hygiene Baseline Every Team Needs in 2026

Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
5 min read
MCP Connector Poisoning: How Compromised npm Packages Hijack Your AI Agent

MCP Connector Poisoning: How Compromised npm Packages Hijack Your AI Agent

Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to 2
5 min read
SAST False Positives in AI-Generated Code: Why 91% of Alerts Are Noise (And How to Fix It)

SAST False Positives in AI-Generated Code: Why 91% of Alerts Are Noise (And How to Fix It)

Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
8 min read
The Hidden Cost of Code Duplication in AI-Assisted Development

The Hidden Cost of Code Duplication in AI-Assisted Development

Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
7 min read
Prompt Injection in AI Coding Agents: How Malicious Dependencies Hijack Your Claude Code Sessions

Prompt Injection in AI Coding Agents: How Malicious Dependencies Hijack Your Claude Code Sessions

Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
8 min read
RSAC 2026: Every AI IDE Is Vulnerable - Here's What That Actually Means for Your Workflow

RSAC 2026: Every AI IDE Is Vulnerable - Here's What That Actually Means for Your Workflow

Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
6 min read
AI Code Review Tools Compared: What Actually Catches Bugs in AI-Generated Code?

AI Code Review Tools Compared: What Actually Catches Bugs in AI-Generated Code?

Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
8 min read
Local-First Code Quality for Claude Code: How to Catch Bugs Before They Leave Your Machine

Local-First Code Quality for Claude Code: How to Catch Bugs Before They Leave Your Machine

Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
8 min read
The Claude Code CVE That Should Change How You Review AI-Generated Code

The Claude Code CVE That Should Change How You Review AI-Generated Code

1
Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
5 min read
A post-mortem on the fastest database breach of 2026 - and the quality gate that would have stopped it cold.

A post-mortem on the fastest database breach of 2026 - and the quality gate that would have stopped it cold.

Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
5 min read
The Vibe Coding Security Checklist: 10 Checks to Run Before You Ship AI-Generated Code

The Vibe Coding Security Checklist: 10 Checks to Run Before You Ship AI-Generated Code

Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to 1
10 min read
AI Writes Code. But Who Checks It?

AI Writes Code. But Who Checks It?

1
Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
3 min read
Running code quality pipelines during AI coding workflows

Running code quality pipelines during AI coding workflows

6
Toni Antunovic - DEV CommunityNavigation menuSearchSearchCloseUser actionsJoinedgithub websiteCloseClosePostCommentTagCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsCommentsComments - dev.to
1 min read
loading...