Malicious repository settings can make AI coding agents run attacker commands
Researchers at Manifold Security disclosed a class of flaws across several command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs automatically on the developer's machine. The command executes outside the agent's sandbox, with the user's privileges, and without any approval prompt, often before the agent even contacts the model. Simply reviewing or opening a malicious project can run attacker code. It triggers when a repository arrives as files with its hidden Git directory intact, such as through a shared drive, archive, or USB stick, rather than a normal clone. Several tools shipped fixes, but some remained vulnerable at disclosure.
- Check
- Update command-line AI coding agents to patched versions, treat opening or reviewing an untrusted repository in an agentic tool as running its code, and prefer plain clones over copied repositories.
- Affected
- Developers using command-line AI coding agents who open untrusted repositories delivered as files with their Git directory intact; repository settings can execute attacker commands outside the sandbox, without approval.
- Fix
- Keep agent tools updated, run them against untrusted code in isolated environments, restrict what the agent can reach, avoid opening repositories from shared drives or archives without inspection, and watch startup commands.