← Founder Notes
Archive

The repo itself just became the attack on your coding agent. manifold security, out september 14,…

Yethikrishna ROriginal on Threads

the repo itself just became the attack on your coding agent. manifold security, out september 14, found eight flaws across seven cli agents where the repository's git config names a command the agent runs on your machine, four still unpatched.

the prompt injection moved into .git.

Context

Manifold Security's GitSpawn post, dated September 1, 2026 with an update the same day, says it found eight findings across seven agents and that four remain unpatched at publication. It describes the mechanism as a repository's git configuration naming a helper command, which runs when an agent invokes a git command that refreshes the index, before a workspace trust prompt or before the model is contacted, so the command runs on the host. The update says Codex and Cursor were also affected, each came back as a duplicate of an earlier report, and both are patched. The post names Claude Code, Goose, Grok Build, Hermes and Qwen Code in detail.

How it compares

The first-party post is dated September 1, not September 14. Four still unpatched is the publication-time statement and current patch status is unverified, and which agents are unpatched was not itemized in the text read. The mechanism is untrusted repository configuration executing code and not text injected into a prompt, so the prompt injection moved into .git is the author's take. This entry cites the research only and repeats no exploit steps. The post's adoption figures for the affected agents are vendor-cited. Secondary coverage from The Hacker News was seen as a snippet only. Earlier notes cover the same research.

Related work

Watch next

  • Vendor advisories and patch status per agent.

Sources

  1. Manifold Security: GitSpawn, AI coding agents git hijack (September 1, 2026)manifold.security

Provenance

The note above is reproduced unedited from the original post, first published on Threads on 23 September 2026 at 03:32 IST. Sources are the papers and datasets the note draws on.

View the original post
Embed this note
<iframe src="https://founder.myndlabs.tech/notes/embed/the-repo-itself-just-became-the-attack-on-DdmwuNIlwzr" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="The repo itself just became the attack on your coding agent. manifold security, out september 14,…"></iframe>

More notes