Opening SecureFlowGitSpawn: Malicious Git Configuration Before Coding-Agent Trust
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

Manifold Security aidefend-sf0047

GitSpawn: Malicious Git Configuration Before Coding-Agent Trust

  • Autonomous Agents
  • System Compromise & RCE
  • Model Evasion & Bypass

Manifold Security reported eight GitSpawn findings across seven AI coding agents. When an attacker delivers a repository with its intact .git/config, a configured core.fsmonitor command can run during status, diff, or background context collection before the agent's trust prompt. The research did not report a malicious real-world compromise, and a normal clone does not carry this local configuration.

Mapped threat techniques

  • AML.T0011.000 User Execution: Unsafe AI Artifacts
  • AML.T0119 Exploit Automated Artifact Processing Pipeline
  • AML.T0050 Command and Scripting Interpreter

Source