The Agentic Post
Breaking
Digital Twins and Physical AI  ·  Humanoid Robots in Manufacturing  ·  AI Data Centers and Water Usage  ·  The AI Chip Supply Chain, Explained  ·  What Is Fine-Tuning? A Plain Explainer  ·  Meta and Sierra Want to Give AI Agents a Front Door to Stores  ·  
Home/AI Safety
GitSpawn: Opening a Folder in Your AI Coding Agent Can Run Code

GitSpawn: Opening a Folder in Your AI Coding Agent Can Run Code

AI Safety

GitSpawn lets a booby-trapped repository run commands the moment it is opened in Claude Code, Cursor, Codex, Grok Build and other AI coding agents, by abusing a git setting the agents trigger on startup.

GitSpawn is a class of vulnerabilities that lets a booby-trapped code repository run commands on a developer’s machine the moment it is opened in an AI coding agent. No prompt is typed and no approval is clicked, and in some cases it fires before the user has even signed in. Researchers at Manifold Security disclosed it on September 2, 2026, and confirmed it in Claude Code, Goose, Hermes Agent, Qwen Code and Grok Build, with variants affecting Cursor and OpenAI’s Codex. Four of the eight tracked issues were still unpatched at disclosure.

How does opening a folder run code?

Almost every coding agent gathers context when it starts by quietly running git commands such as git status or git diff. Those commands make git refresh its internal index. Git has a documented performance setting, core.fsmonitor, that names a helper program to run on every index refresh, and it reads that setting from the repository’s own .git/config file.

So a malicious repository can put any command it likes in that setting. When the agent runs its routine context check, the command executes with the full privileges of the logged-in user. It runs outside the agent’s sandbox and never appears in the permission prompts, because from the agent’s point of view it only ran git status.

Can it reach me through a normal git clone?

No, and that is the main limit on the attack. Clone, fetch and pull never transmit a repository’s .git/config, so a project pulled from GitHub the normal way is not affected. The poisoned repo has to arrive as raw files with its .git folder intact: a zip file, a shared drive, a synced folder or a USB stick. That is exactly how contractors, consultants and colleagues routinely hand projects over, which is what makes it realistic.

Which tools are affected, and what is patched?

  • Claude Code: affected, with four flaws tracked. One, in the ultrareview command, abuses a different git configuration key and was deliberately left unnamed by the researchers. Claude Code is installed more than 77 million times a month on npm.
  • Goose: fixed, assigned CVE-2026-72718.
  • Hermes Agent: assigned CVE-2026-71963 after the vendor did not respond to six contact attempts.
  • Cursor and Codex: both patched after reports, each flagged as a duplicate of findings other researchers had filed independently.
  • Qwen Code and Grok Build: confirmed vulnerable at disclosure.

Patch status may have moved since September 2, so check each vendor’s changelog rather than relying on this list.

What should developers do now?

If you receive a project as files rather than through a clone, open .git/config in a plain text editor before pointing any AI agent at the folder, and look for fsmonitor or any other entry that names a program. If in doubt, delete the .git folder and re-clone from the real remote. Keep your agents updated. For vendors, the fix the researchers recommend is simple: explicitly disable core.fsmonitor on every background git call.

GitSpawn fits the pattern of agent supply-chain risk we have been tracking, alongside slopsquatting fake packages and agents leaking screenshots to public GitHub. In each case the agent does something ordinary, and the danger sits in what that ordinary action quietly triggers. It is also a reminder that sandboxing the agent does not help when the dangerous code runs in a process the sandbox never sees.

Read the full write-up of the Manifold Security findings.

Up Next
How to Use AI for Meeting Notes

How to Use AI for Meeting Notes

How-To

A practical guide to using AI for meeting notes, covering structure, verifying action items, and when to circulate a draft versus a final record.

AI-generated meeting notes are genuinely useful, and also genuinely easy to trust too much without a quick review pass. A few habits make the difference.

Ask for structure, not a transcript. Decisions made, action items with owners, open questions, separated clearly, rather than a chronological wall of text taking as long to read as the meeting itself.

Verify action items and owners specifically. Assigning the wrong owner, or missing one, is the single most consequential error, since it directly affects whether real work gets done. Worth a careful read before circulating, even if you skim the rest.

Watch for misattributed quotes in multi-speaker meetings, especially with similar-sounding voices or crosstalk. If a specific quote matters, double-check who it’s attributed to.

For routine meetings, AI notes can go out directly. For anything consequential, circulate a draft first, “here’s the draft, flag anything off”, catches errors before they become the official record. See our prompt engineering guide for more on structured output, and Anthropic’s own documentation for technical depth.