GitSpawn: Untrusted repos can execute code via AI coding agents(manifold.security) |
GitSpawn: Untrusted repos can execute code via AI coding agents(manifold.security) |
Followed by:
> Delivery is worth being precise about, because git never carries this. Cloning a hostile URL does nothing, and neither does fetch or pull.
AI slop nothing burger. The “exploit” has nothing to do with coding agents.
It's pretty small potatoes, but it is a harness ~bug that they treat this so poorly. It getting triggered before some of them even ask you if you trust the directory is pretty bad.