Malicious Git Configs Threaten AI Coding Agents
Recent disclosures report that malicious repository-level Git configuration can trigger attacker-controlled commands in coding agents before trust prompts or model interaction. The issue affects open-source agents such as Goose, Qwen Code, and Hermes Agent alongside proprietary tools, making repository isolation, sandboxing, least privilege, and remediation tracking immediate production concerns.
Sources (2)
Updated Sep 3, 2026