Malicious .git configs can make coding agents run attacker code
Manifold Security’s GitSpawn research shows seven CLI coding agents can execute a repo’s core.fsmonitor (or similar) command outside the sandbox with no approval prompt. goose, Claude Code, Cursor, and Codex have patches; Hermes Agent, Qwen Code, and Grok Build were still open on retest.
