# Manifold Security finds eight flaws in seven AI coding agents that run commands from a repository’s git config

> A repository’s own .git/config can make AI coding agents run commands before any trust prompt. Manifold Security lists which agents are fixed and which are not.

FireAI Security & Research Team (HisnLabs) · Published 2026-09-30
Canonical: https://hisnlabs.com/en/news/gitspawn-malicious-git-config-ai-coding-agents

Manifold Security has disclosed eight flaws across seven AI coding agents in which a folder's own git settings make the agent run a command on the developer's computer, [The Hacker News reported](https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html) on 2 September. The research is called GitSpawn. In several agents the command runs before the tool asks whether the folder is trusted.

## Background

When a coding agent opens a project, it runs git commands to learn the current branch and which files changed. Git has a performance setting, core.fsmonitor, that names a program git runs to find changed files. If the setting comes from the repository's own .git/config, the repository chooses the program [[1]](https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html).

## What the report describes

Manifold found that a crafted .git/config can name any command, which then runs with the developer's privileges, outside the agent's sandbox and without an approval prompt. The report says exploitation needs a folder that still contains its .git directory, such as one delivered as an archive, on a shared drive or on a USB stick, and not an ordinary clone [[1]](https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html).

Timing differs by agent. The command runs before the workspace-trust prompt in Claude Code and Hermes Agent, before authentication in Qwen Code, and on the first keystroke in Grok Build [[1]](https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html).

The report lists goose (version 1.44.0 and later), Cursor and Codex as fixed, and Claude Code as partly fixed from version 2.1.196. Hermes Agent, Qwen Code and Grok Build are listed as unpatched, as is a second path in Claude Code that Manifold confirmed on version 2.1.252. It says no exploitation has been observed and that the Hermes Agent report has not been triaged despite repeated attempts to reach the vendor [[1]](https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html).

> A command that runs quietly and then connects out still has to reach the network. FireAI asks before an unfamiliar process goes online. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Implications for Mac users

Developers who open project folders received from others, especially folders copied rather than cloned, with one of the listed agents are the exposed group. The report gives no operating-system limit, so a Mac used for development falls within it [[1]](https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html).

## Recommendations

1. Before opening a folder received as an archive, from a shared drive or from a USB stick, read its .git/config file.
2. Look for core.fsmonitor, core.hooksPath and filter entries, which the report names as the settings to inspect.
3. Prefer a fresh git clone from the original host over copying a whole folder.
4. Update the agent you use, and check the vendor’s notes for the fixes listed above.

## Relevance to FireAI

FireAI does not read git settings or stop a local command from running. It is a network firewall: if the command starts a download or sends files out, the connection from a process with no rule triggers a prompt in Alert mode, and the [world map](https://hisnlabs.com/en/docs/world-map) shows where it was headed. In [Under attack mode](https://hisnlabs.com/en/docs/security-modes), only apps with an explicit Allow rule may connect.

> Open an unfamiliar project on a Mac that is watching its connections. FireAI names the app and the destination before anything leaves. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Limitations

This account relies on one report. It does not say how many developers used the affected versions, and its patch list may have changed since 2 September. It does not state how the partly fixed Claude Code path differs from the unpatched one.

Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days.

## Sources

- [The Hacker News, 2 September 2026: Malicious .git configs can make Claude, Codex, Cursor and other AI coding agents run commands](https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html)
