The supplied results describe a class of AI coding-agent attacks in which an untrusted repository can trigger code execution through repository configuration, setup behavior, hooks, or indirect prompts, potentially exposing credentials or opening a reverse shell. Reports say Claude Code is affected and that Anthropic responded to related issues by tightening trust prompts, blocking external-tool execution, and requiring approval for some API calls; other coding agents and unattended CI/CD workflows may share similar structural exposure. However, the snippets do not directly substantiate the specific name “GitSpawn” or clearly establish that Manifold Security discovered this exact repository-triggered flaw—the Manifold result shown concerns spoofed Git identity metadata in automated code review.
The radar already tracks this development class in `radar:repository-content-agent-injection`: untrusted repository content steering coding agents despite sandboxing. It bears directly on Scott’s SiloOS containment architecture and potentially his `ask` terminal agent’s non-mechanical approval boundary, but the supplied evidence does not substantiate the specific “GitSpawn” name or Manifold attribution well enough to establish a distinct new incident.
ip:framework.siloosip:concept.sandboxed-executionip:concept.taint-trackingip:concept.architectural-containmentdev:project.silo-osdev:project.askradar:repository-content-agent-injectionradar:concept.coding-agent-security
queries asked of Scott's wikis
- untrusted repository boundaries for coding agents
- sandboxed startup for unattended coding workflows
- agent tool execution approval and least privilege
- repository instructions hooks and prompt injection
- coding-agent secrets isolation in CI/CD
- software supply-chain threat model for agent harnesses
2026-09-07T02:32:56Z
Repeated coverage and the stale-window check have produced no substantive GitSpawn-specific validation or change in practical scope, and no concrete confirming event is pending. Retire this episode as faded, not disproved; the broader repository-containment concern remains relevant independently.
2026-09-05T02:23:32Z
The latest attachment repeats the original allegation without adding technical validation. Correcting the inherited maturity: separate repository-security incidents support the containment lesson, not GitSpawn’s specific exploit or cross-agent scope, which remain uncorroborated.
2026-09-05T02:21:58Z
evidence attached: hn.story.49572279 — shared external link with case evidence
2026-09-05T00:28:15Z
The refreshed METR comments remain amplification of a separate incident and add no GitSpawn-specific reproduction, affected-agent matrix, vendor response, or mitigation. The broader repository-containment lesson is established, while the named exploit’s practical reach remains uncertain.
2026-09-03T23:33:24Z
The pull-request credential-theft anecdote broadens the corroborated repository supply-chain concern into code-review workflows, but its headline-only evidence does not validate GitSpawn’s mechanism, cross-agent scope, or practical prevalence. The case remains a useful containment pattern rather than a newly established named exploit.
2026-09-03T23:22:26Z
evidence attached: hn.story.49557967 — A concrete pull-request credential-theft attempt independently reinforces the risk of repository and code-review supply-chain attacks against agent workflows.
2026-09-03T12:31:21Z
The refreshed discussion adds no GitSpawn-specific reproduction, affected-agent matrix, vendor response, or mitigation. It remains repetitive amplification around the already-corroborated broader containment risk, while the named exploit’s practical reach and cross-agent scope stay uncertain.
2026-09-03T11:24:51Z
The new attachment is another repost of the same GitSpawn allegation and adds no reproduction, vendor response, or affected-agent matrix. The broader repository-containment lesson remains corroborated, while the named exploit’s practical reach is still uncertain and may require narrower non-clone repository-transfer conditions.
2026-09-03T11:21:58Z
evidence attached: hn.story.49548304 — Direct coverage of the existing GitSpawn repository-hijack episode, reinforcing its relevance to unattended coding-agent security.
2026-09-03T10:28:45Z
The refreshed comments remain focused on the separate METR incident and add no GitSpawn-specific reproduction, affected-agent matrix, or vendor response. The broader repository-containment risk is corroborated, but this named exploit and its cross-agent scope remain weakly substantiated.
2026-09-03T06:30:25Z
The refreshed discussion adds no GitSpawn-specific reproduction, affected-agent evidence, or vendor response; it remains repetitive amplification of a separate METR incident. The broader containment lesson stands, while the named flaw and claimed cross-agent scope remain weakly substantiated.
2026-09-03T05:26:03Z
Refreshed METR discussion remains repetitive and concerns a separate incident; it adds no reproduction, affected-agent matrix, or vendor response for GitSpawn. The broader repository-containment lesson stands, but the specific mechanism and cross-agent scope remain weakly substantiated.
2026-09-02T23:37:01Z
The METR report reinforces the broader need to isolate coding-agent workflows, but it is a separate incident and does not corroborate GitSpawn’s specific mechanism, affected-agent scope, or attribution. With no direct reproduction or vendor response, this case is substantively unchanged and can cool.
2026-09-02T23:22:24Z
evidence attached: hn.story.49543841 — The METR first-party incident investigation is independent corroboration that repository and coding-agent workflows can create serious compromise paths.
2026-09-02T15:48:16Z
The independent llms.txt exploit corroborates the broader operational conclusion that untrusted project guidance can drive coding agents into arbitrary tool execution, strengthening the case for startup isolation and approval boundaries. It does not independently reproduce GitSpawn, confirm the claimed cross-agent scope, or resolve whether attacker-controlled local `.git/config` commonly reaches victims.
2026-09-02T15:23:44Z
evidence attached: hn.story.49537462 — This independently reported llms.txt attack corroborates the broader risk that untrusted repository or web guidance can become executable instructions for coding agents.
2026-09-02T09:36:34Z
A new technical explanation identifies Git-controlled executables such as `.git/config`’s `core.fsmonitor` as the likely repository-triggered path, making the allegation concrete and structurally plausible. It still lacks an independent reproduction, affected-agent matrix, or vendor confirmation, so it remains uncorroborated.
2026-09-02T08:30:51Z
The added HN link repeats the same cross-agent allegation without mechanism, reproduction, affected configurations, or independent confirmation. It broadens distribution but does not strengthen the case beyond a weakly substantiated instance of the known untrusted-repository attack class.
2026-09-02T08:22:16Z
evidence attached: hn.story.49533331 — shared external link with case evidence
2026-09-01T19:00:51Z
No substantive corroboration or technical detail has arrived; the case remains a potentially important but weakly substantiated instance of the already-known untrusted-repository attack class.
2026-09-01T18:42:40Z
grounded: known/medium — The radar already tracks this development class in `radar:repository-content-agent-injection`: untrusted repository content steering coding agents despite sandb
2026-09-01T18:39:29Z
case created — The disclosure describes a concrete and transferable repository-level attack path against coding-agent execution environments.