The coding agent just ran the attacker's git command first. manifold security, reporting oct 8,…
the coding agent just ran the attacker's git command first. manifold security, reporting oct 8, found six high-severity flaws where agents execute malicious git commands before user approval.
the trust prompt now comes after the damage.
Context
Verified date: Manifold Security's blog, The git you didn't run, is dated Sep 1, 2026, and The Hacker News (Sep 2, 2026) reports that Manifold disclosed eight security flaws across seven command-line AI coding agents, four still unpatched at publication. A repository's own Git configuration names a command that the agent runs on the developer's machine.
Manifold says agents run git commands in the background to gather context, on some agents before the workspace-trust prompt and before authentication. The Cloud Security Alliance (Sep 3 and Sep 4, 2026) names the class GitSpawn.
The behavior matches: an agent runs an attacker-supplied git command before approval. The disclosure is dated Sep 1 and 2, 2026, not Oct 8. The sources count eight flaws across seven agents, so 'six high-severity flaws' was not seen in the sources read, so unsupported here, not refuted. 'The trust prompt now comes after the damage' is the author's opinion.
Related work
- Cloud Security Alliance: GitSpawn research note ↗Sep 3, 2026.
- BugB: untrusted .git/config executes code through the agent ↗Playbook for the same class.
- Sonar: how Claude executed code before you click trust ↗Apr 30, 2026; an earlier trust prompt bypass.
Watch next
- Find what was reported on Oct 8 and how many flaws were rated high severity.
Sources
- Manifold Security: the git you didn't runmanifold.security
- The Hacker News: malicious .git configs can make AI coding agents run codethehackernews.com
- Cloud Security Alliance: GitSpawn, malicious git configs hijack AI coding agentslabs.cloudsecurityalliance.org
Provenance
The note above is reproduced unedited from the original post, first published on Threads on 11 October 2026 at 19:50 IST. Sources are the papers and datasets the note draws on.
View the original post ↗Embed this note
More notes
The air is now being asked to keep its own ledger
the air is now being asked to keep its own ledger: ecmwf’s aifs compo becomes the first ai model to forecast atmospheric composition globally every three hours, cleanair simulates 365 days of pm2.5 over china in ten seconds, and a unified framework maps six pollutants at one kilometer across the whole country. the air now files its own composition report.
read the note →The current is now being asked to draw its own map
the current is now being asked to draw its own map: china’s langya 2.0 predicts six ocean phenomena including internal waves and mesoscale eddies, a deep net called wenhai resolves eddies globally with air sea flux formulas built in, and scripps infers surface currents from the way temperature patterns deform in satellite images. the ocean now files its own circulation report.
read the note →The soil is now being asked to report its own carbon
the soil is now being asked to report its own carbon: a nix color sensor paired with generative data augmentation predicts soil organic carbon without a lab, random forest drives 74 percent of soil health mapping studies, and sentinel 2 tracks five year carbon change across france and italy from 922 samples. the dirt now files its own carbon account.
read the note →