← Founder Notes
Archive

The coding agent just ran the attacker's git command first. manifold security, reporting oct 8,…

Yethikrishna ROriginal on Threads

the coding agent just ran the attacker's git command first. manifold security, reporting oct 8, found six high-severity flaws where agents execute malicious git commands before user approval.

the trust prompt now comes after the damage.

Context

Verified date: Manifold Security's blog, The git you didn't run, is dated Sep 1, 2026, and The Hacker News (Sep 2, 2026) reports that Manifold disclosed eight security flaws across seven command-line AI coding agents, four still unpatched at publication. A repository's own Git configuration names a command that the agent runs on the developer's machine.

Manifold says agents run git commands in the background to gather context, on some agents before the workspace-trust prompt and before authentication. The Cloud Security Alliance (Sep 3 and Sep 4, 2026) names the class GitSpawn.

How it compares

The behavior matches: an agent runs an attacker-supplied git command before approval. The disclosure is dated Sep 1 and 2, 2026, not Oct 8. The sources count eight flaws across seven agents, so 'six high-severity flaws' was not seen in the sources read, so unsupported here, not refuted. 'The trust prompt now comes after the damage' is the author's opinion.

Related work

Watch next

  • Find what was reported on Oct 8 and how many flaws were rated high severity.

Sources

  1. Manifold Security: the git you didn't runmanifold.security
  2. The Hacker News: malicious .git configs can make AI coding agents run codethehackernews.com
  3. Cloud Security Alliance: GitSpawn, malicious git configs hijack AI coding agentslabs.cloudsecurityalliance.org

Provenance

The note above is reproduced unedited from the original post, first published on Threads on 11 October 2026 at 19:50 IST. Sources are the papers and datasets the note draws on.

View the original post
Embed this note
<iframe src="https://founder.myndlabs.tech/notes/embed/the-coding-agent-just-ran-the-attacker-s-DeW3BLZjf5Q" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="The coding agent just ran the attacker's git command first. manifold security, reporting oct 8,…"></iframe>

More notes