Manifold Security has disclosed eight flaws across seven AI coding agents in which a folder's own git settings make the agent run a command on the developer's computer, The Hacker News reported on 2 September. The research is called GitSpawn. In several agents the command runs before the tool asks whether the folder is trusted.
Background
When a coding agent opens a project, it runs git commands to learn the current branch and which files changed. Git has a performance setting, core.fsmonitor, that names a program git runs to find changed files. If the setting comes from the repository's own .git/config, the repository chooses the program [1].
What the report describes
Manifold found that a crafted .git/config can name any command, which then runs with the developer's privileges, outside the agent's sandbox and without an approval prompt. The report says exploitation needs a folder that still contains its .git directory, such as one delivered as an archive, on a shared drive or on a USB stick, and not an ordinary clone [1].
Timing differs by agent. The command runs before the workspace-trust prompt in Claude Code and Hermes Agent, before authentication in Qwen Code, and on the first keystroke in Grok Build [1].
The report lists goose (version 1.44.0 and later), Cursor and Codex as fixed, and Claude Code as partly fixed from version 2.1.196. Hermes Agent, Qwen Code and Grok Build are listed as unpatched, as is a second path in Claude Code that Manifold confirmed on version 2.1.252. It says no exploitation has been observed and that the Hermes Agent report has not been triaged despite repeated attempts to reach the vendor [1].
Implications for Mac users
Developers who open project folders received from others, especially folders copied rather than cloned, with one of the listed agents are the exposed group. The report gives no operating-system limit, so a Mac used for development falls within it [1].
Recommendations
- Before opening a folder received as an archive, from a shared drive or from a USB stick, read its .git/config file.
- Look for core.fsmonitor, core.hooksPath and filter entries, which the report names as the settings to inspect.
- Prefer a fresh git clone from the original host over copying a whole folder.
- Update the agent you use, and check the vendor’s notes for the fixes listed above.
Relevance to FireAI
FireAI does not read git settings or stop a local command from running. It is a network firewall: if the command starts a download or sends files out, the connection from a process with no rule triggers a prompt in Alert mode, and the world map shows where it was headed. In Under attack mode, only apps with an explicit Allow rule may connect.
Limitations
This account relies on one report. It does not say how many developers used the affected versions, and its patch list may have changed since 2 September. It does not state how the partly fixed Claude Code path differs from the unpatched one.
Try FireAI, by HisnLabs free for 17 days.