
Context gathering achieved code execution.
The repo answered before the prompt.
Manifold Security found that several command-line coding agents automatically ran Git commands to gather project context. A repository’s local .git/config could point Git’s legitimate fsmonitor setting at an attacker-controlled helper, so background status or diff checks executed code outside the agent sandbox before any prompt or approval. The delivery caveat matters: an ordinary clone does not carry the local config; the repository has to arrive with its .git directory intact, such as through an archive or shared folder. Several products patched affected versions; no exploitation was reported at publication.










