2026-10-11 17:12 UTC

Manifold Security claims GitSpawn lets malicious repositories execute code through Claude Code and other coding agents, requiring hardened repository startup and tool-execution boundaries for unattended workflows.

state: expiredheat: lowuncertainty: highknownscott: mediumcoding-agents agentic-security software-supply-chainManifold SecurityAnthropic

What is this?

The supplied results describe a class of AI coding-agent attacks in which an untrusted repository can trigger code execution through repository configuration, setup behavior, hooks, or indirect prompts, potentially exposing credentials or opening a reverse shell. Reports say Claude Code is affected and that Anthropic responded to related issues by tightening trust prompts, blocking external-tool execution, and requiring approval for some API calls; other coding agents and unattended CI/CD workflows may share similar structural exposure. However, the snippets do not directly substantiate the specific name “GitSpawn” or clearly establish that Manifold Security discovered this exact repository-triggered flaw—the Manifold result shown concerns spoofed Git identity metadata in automated code review.

Why it matters to Scott

The radar already tracks this development class in `radar:repository-content-agent-injection`: untrusted repository content steering coding agents despite sandboxing. It bears directly on Scott’s SiloOS containment architecture and potentially his `ask` terminal agent’s non-mechanical approval boundary, but the supplied evidence does not substantiate the specific “GitSpawn” name or Manifold attribution well enough to establish a distinct new incident.
ip:framework.siloosip:concept.sandboxed-executionip:concept.taint-trackingip:concept.architectural-containmentdev:project.silo-osdev:project.askradar:repository-content-agent-injectionradar:concept.coding-agent-security
queries asked of Scott's wikis
  • untrusted repository boundaries for coding agents
  • sandboxed startup for unattended coding workflows
  • agent tool execution approval and least privilege
  • repository instructions hooks and prompt injection
  • coding-agent secrets isolation in CI/CD
  • software supply-chain threat model for agent harnesses

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (8) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnGitSpawn: A Single Flaw Lets Untrusted Repos Run Code in Claude Code, and Others0xmagic010
🟧 echo.blog ⭐Manifold Security reports a repository-triggered flaw that allows untrusted projects to run code through Claude Code and other AI coding ageManifold Security——
🟧 hnA Single Flaw Lets Untrusted Repos Run Code in Claude Code, Codex, Cursor, Grokaxsharma27
🟧 hnResearchers trick Fortune-500 AI agents into running arbitrary code via llms.txtsbulaev10
🟧 hnMETR Report on OpenAI / Hugging Face Hacking Incidentstikit122105
🟧 hnGitSpawn: Flaw Lets Untrusted Repos Run Code in Claude Code, Codex, Cursor, Grokchillax40
🟧 hnA Stranger's Pull Request Almost Stole My Cloud Credentialssyumei20
🟧 hnGitSpawn: Untrusted repos can execute code via AI coding agentsfourfire30

Interpretation history

Decision trace