GitSpawn: Untrusted repos can execute code via AI coding agents
manifold.security
GitSpawn: Untrusted repos can execute code via AI coding agents
1–6 of 6 posts
Re: GitSpawn: Untrusted repos can execute code via AI coding agents
#2GitSpawn: A Single Flaw Let's Untrusted Repos Run Code in Claude Code, Codex, Cursor, and Grok
Re: GitSpawn: Untrusted repos can execute code via AI coding agents
#3[flagged]
Re: GitSpawn: Untrusted repos can execute code via AI coding agents
#4> Git reads that setting from the repository's own .git/config. So a repository can ship this:
Followed by:
> Delivery is worth being precise about, because git never carries this. Cloning a hostile URL does nothing, and neither does fetch or pull.
AI slop nothing burger. The “exploit” has nothing to do with coding agents.
Re: GitSpawn: Untrusted repos can execute code via AI coding agents
#5> Git reads that setting from the repository's own .git/config. So a repository can ship this: Followed by: > Delivery is worth being precise about, because git never carries this. Cloning a hostile URL does nothing, and neither does fetch or pull. AI slop nothing burger. The “exploit” has nothing to do with coding agents.
> AI slop nothing burger. The “exploit” has nothing to do with coding agents.
It's pretty small potatoes, but it is a harness ~bug that they treat this so poorly. It getting triggered before some of them even ask you if you trust the directory is pretty bad.
Re: GitSpawn: Untrusted repos can execute code via AI coding agents
#6[dead]