Ten minutes is enough. A developer clones a repo that looks like a sample app, points a command-line coding agent at the folder, and steps away. The agent reads Git the way every serious tool does. Inside that repo’s own config is a command the project named. The agent executes it as the developer, outside its sandbox, with no approval prompt. Manifold Security just showed that pattern across seven CLI agents, including Claude, Codex, and Cursor. Four were still unpatched when the research landed. That is a cybersecurity hole your laptop standard never named.

You already worry about what an agent might say. Worry about what it will run because Git told it to.

The Config File Issued the Order

Manifold’s disclosure is going to annoy you because the mechanism is old. A Git repository is source, history, and a configuration that can name programs: credential helpers, pagers, diff drivers, SSH wrappers, filesystem monitors. A hostile clone can set those keys before anyone reviews a single line of application code. When the coding agent starts its normal workflow, it shells out to Git. Git honors the repo. The named binary runs in the user’s security context.

The vendor sandbox does not wrap that child process. There is no click-through. Exploitation requires the repository to arrive on the machine. That arrival looks like a clone, a submodule, a zip attached to a ticket, or a “quick look” at a partner SDK. None of those events will show up as a brute-force storm on your VPN concentrator. They show up as a developer doing the job you hired them to do.

Illustration of an AI coding agent executing attacker-controlled commands from a cloned repository
CLI coding agents can inherit a repo’s Git helpers and run them as the developer, outside the sandbox the product page advertised.

Eight flaws across seven agents point to a shared design bet. Each tool treated Git configuration as infrastructure. On a laptop that just cloned untrusted code, that file is attacker-controlled input. Developers treat clone as the start of work. For these agents, clone is execution.

Your org policy might say people only pull from approved GitHub organizations. That rule lasts until someone forks a demo, vendors a plugin, or drops a conference workshop repo into a spike. The agent is faster than your review. Speed is why you bought it. Speed is also why a config key beats every awareness poster you printed last quarter.

Attackers Already Drive Agents Through the Network

The inbound problem on the laptop has an outbound twin. Unit 42 published an investigation of an AI-assisted intrusion in which autonomous agents helped an attacker move through an enterprise network in a matter of hours. Steal the tempo for your tabletop. Brute-force attempts still announce themselves as repetitive noise. An agent that iterates, retries, and chains tools looks like a competent contractor finishing a change window.

Overview graphic from Unit 42's investigation of an AI-assisted enterprise intrusion
Unit 42’s case shows autonomous agents compressing an enterprise break-in into hours, the same class of tool your developers now run locally with Git privileges.

Your firewall still records a source address. Your threat-protection stack still hunts malware families and known callback patterns. Neither is trained to care when a blessed CLI on a developer workstation spawns a helper Git named, or when an agent on the far side of the wire walks shares and identity systems at a pace no human operator matches. Cyber security teams that filed “AI risk” under acceptable-use policy, and left execution under endpoint hope, will watch both paths land in the same week.

The common failure is where you placed trust. You wrapped the model. The path around the model still runs as a person, with that person’s keys, and with Git’s willingness to execute whatever a repo configured. That is a privileged intern with root-adjacent habits, hired through a package manager, never enrolled in your joiner-mover-leaver process.

Cybersecurity Hardening Has to Reach the Clone

Stop treating unknown clones as documents. Treat them as media you would refuse to mount on a domain-joined desktop.

Immediate actions are physical in spirit. Developers who must inspect unfamiliar code do it in a VM or container that holds no SSO cookies, no cloud CLIs, and no SSH keys into production. Before any agent starts, a person reads .git/config and the hooks directory. Keys that name programs get explained or the clone gets deleted. If your Git build can ignore repo-local config for automated tools, turn that on for agent accounts tonight. Standing “ask me first” toggles in the agent UI do not cover a child process the agent never surfaced as a prompt.

The agent process should not inherit a full home directory. Give it a working tree and a toolchain. Keep ~/.ssh, browser profiles, password-manager sockets, and CI tokens out of its view. If a coding assistant needs to push, it uses a scoped token for that repo, not the developer’s org-owner credential. You already know how to do this for build agents. The laptop is now a build agent that talks.

Ongoing security hardening looks like software inventory, not a lunch-and-learn. Pin CLI agent versions and own the update SLA. Four of seven tools were unpatched on disclosure day, so “whatever the last upgrade pulled” is not a control. Log process ancestry so threat detection can fire when an agent binary spawns a shell, curl, or ssh the developer did not type. Egress policy should make a surprise reverse tunnel obvious even when the parent process is on the allowlist.

Defense in depth on this path is unglamorous. Least privilege on the laptop, a Git config review gate, and an incident response playbook titled “poisoned clone.” When someone says the agent did something weird, you collect the working tree, the Git config, and the process tree first. You do not open with which model they selected. Most IR trees still start at the edge: VPN, mail gateway, firewall denies. This execution path never crosses those chokepoints. The first artifact is a local Git object and a child process. If your tabletop assumes the attacker had to beat MFA on a web app, you will burn the first hour on the wrong door.

Put developer agents on the same asset list as privileged admin utilities. They write code, they hold tokens, they can push. That is production-adjacent even when the laptop sits on guest wireless. You do not need a new product category to survive this week. You need a standing rule. No agent, no CI runner, and no “helpful” CLI gets to treat a freshly cloned repository as trusted input. Git config is code. Read it like code, or wait until it runs.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.