Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • GitSpawn: A Single Flaw Let's Untrusted Repos Run Code in Claude Code, Codex, Cursor, and Grok
  • > Git reads that setting from the repository's own .git/config. So a repository can ship this:

    Followed by:

    > Delivery is worth being precise about, because git never carries this. Cloning a hostile URL does nothing, and neither does fetch or pull.

    AI slop nothing burger. The “exploit” has nothing to do with coding agents.

  • > AI slop nothing burger. The “exploit” has nothing to do with coding agents.

    It's pretty small potatoes, but it is a harness ~bug that they treat this so poorly. It getting triggered before some of them even ask you if you trust the directory is pretty bad.

GitSpawn: Untrusted repos can execute code via AI coding agents · Birbla