AI Coding Agents Can Execute Malicious Code Just by Opening a Repository
Security researchers have identified a class of attacks where malicious repositories can compromise AI coding agents without developers ever manually running any code. When an agent opens a project to understand its context, it may read configuration files, Git history, and agent-specific instruction files that attackers can weaponize. A documented attack method called GitSpawn exploits Git's core.fsmonitor setting, causing attacker-controlled code to execute when agents perform routine operations like 'git status' or 'git diff'. Researchers found several popular coding agents affected, including Claude Code, OpenAI Codex, Cursor, and Goose, among others. Beyond code execution, repositories can also embed prompt injection instructions designed to manipulate an agent's behavior, such as exfiltrating environment variables, expanding the attack surface well beyond traditional code-based threats.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in