
Research teams from the University of York and the University of Calgary analyzed Reddit posts related to coding AI issues and found that AI agents, due to excessive permissions, overwrote files, deleted important data, and even generated malicious code.
The research team used a crawler to collect 3,801 popular posts tagged with large language models (LLMs) between February 2023 and March 2026. From these, they selected 446 posts about coding AI security and analyzed more than 6,000 user comments below the posts.

Regarding timing, the study noted that Reddit had the highest number of posts about AI coding issues around summer 2025, with July 2025 recording the most issues.

By tool, Cursor had the most reported issues, followed by Claude, Codex, Copilot, Windsurf, VSCode, Replit, and Cline.

The issue-type classification chart shows that Cursor encountered many “runtime security issues” and “unauthorized data access” incidents, negatively affecting production environments. Claude, meanwhile, encountered many “risks related to integration with third-party tools.” The relevant information is as follows:




