Manifold Security
aidefend-sf0047
GitSpawn: Malicious Git Configuration Before Coding-Agent Trust
- Autonomous Agents
- System Compromise & RCE
- Model Evasion & Bypass
Manifold Security reported eight GitSpawn findings across seven AI coding agents. When an attacker delivers a repository with its intact .git/config, a configured core.fsmonitor command can run during status, diff, or background context collection before the agent's trust prompt. The research did not report a malicious real-world compromise, and a normal clone does not carry this local configuration.
Mapped threat techniques
AML.T0011.000User Execution: Unsafe AI ArtifactsAML.T0119Exploit Automated Artifact Processing PipelineAML.T0050Command and Scripting Interpreter