A repository received as files can make multiple coding agents run attacker code before trust or approval.
The malicious .git configuration must survive delivery; an ordinary clone does not carry it.
Claude Code, Goose, Hermes Agent, Qwen Code, Grok Build, Codex and Cursor command-line AI coding agents on developer workstations.
Pre-trust arbitrary code execution as the developer
The changed boundary is execution before the agent asks for trust, authentication, or command approval across multiple products.
Detail and 1 source
The attacker prepares a directory whose .git/config selects a helper through core.fsmonitor or another command-bearing Git setting. The directory must arrive through an archive, shared drive, synchronization folder, or removable media with both the local configuration and helper intact.
When an affected agent gathers context with git status, git diff, or an equivalent command, Git executes the selected helper outside the sandbox as the developer. Manifold’s September 1 retest found current unpatched paths still exposed, so received repositories should be treated as executable content before an agent opens them.
- Pre-fix images still accepted
- Yes
Answers assess the cross-product finding as a whole; vendor-specific evidence is identified in each reason.