GitSpawn: The AI Coding Agent Runs Attacker Code Before You Approve Anything

September 3, 2026 · SPR{K}3 Research

You get a repo as a zip. You extract it, open it in your AI coding agent, and the agent's first background git status executes a shell command the repo brought with it — as you, outside the sandbox, before the workspace-trust prompt fires. No prompt submitted. No tool call approved. The model never ran.

That is GitSpawn, disclosed by Manifold Security and covered by The Hacker News on September 2. Eight flaws across seven command-line AI coding agents. Four still unpatched when Manifold retested on September 1.

The primitive

core.fsmonitor is a Git performance setting whose value is a command line Git executes to find changed files. Git reads it from the repository's own .git/config. Any operation that refreshes the index — git status, git diff, git log --stat — runs that command.

AI coding agents call those operations in the background at session startup, before the workspace-trust dialog, before authentication, before the first keystroke — to render the UI. And they do it without stripping the repository-supplied setting.

The repository has to arrive as files with .git intact — archive, sync folder, USB stick; git clone doesn't preserve it. git fsmonitor abuse is known — Cobalt wrote it up in December, Sonar reported the same sink in Claude Code in April, and the workspace-trust-bypass shape has prior CVEs in VS Code (CVE-2021-43891) and JetBrains IDEs (CVE-2025-68269, untrusted-remote-project bypass fixed in IntelliJ IDEA 2025.3).

The affected agents

Per Manifold's GitSpawn writeup and The Hacker News:

Claude Code, Hermes fire before workspace-trust; Qwen Code before authentication; Grok Build on first keystroke.

Why the class keeps landing

Manifold's framing: "The vulnerability is not in the model, or in anything new. It is in the ordinary plumbing underneath, the subprocess an agent spawns at session startup to work out where it is."

Recent findings all share the pattern — GhostApproval (approval dialog names one file, OS write follows a symlink to another), Cursor CLI pre-trust command execution (.cursor/worktrees.json runs before the trust prompt), CVE-2026-35603 (world-writable ProgramData compromises every user of Claude Code, Cursor, Codex CLI, and Gemini CLI on the host), Amazon Kiro Powers exfil (a POWER.md steering file exfiltrates on first message), and GitSpawn itself. The through-line: the boundary the vendor advertises — trust dialog, approval prompt, sandbox flag, auth check — sits after the substrate the agent actually touches on the way in. The plumbing runs first.

Vendor responses

Update — Sept 21, 2026

Since Manifold's Sept 1 retest: Hermes Agent shipped a fix. Nous Research merged PR #101483 on Sept 2, closing GHSA-7x36-8jrh-v4pw / CVE-2026-71963 by routing automatic git probes through a hardened env that neutralizes core.fsmonitor, core.hooksPath, pager, editor, and credential helpers — a direct port from google-gemini/gemini-cli #28792. Qwen Code has an open fix PR (#11669). Grok Build remains unpatched at v1.0.13; xAI closed Manifold's report as a duplicate of a July 1 report they had marked "informative." Claude Code's ultrareview second sink has no public advisory through v2.1.270 (Sept 12).

Where the defense actually lives

Obvious mitigations: git config --global core.fsmonitor false, audit .git/config for core.fsmonitor, core.hooksPath, and attr.tree in any repo that arrived as files, pin agent versions above the fixed builds.

But the primitive is a legitimate Git feature and the sink is a subprocess the agent has to run. Vendors that ship a fix strip the setting on background calls (git -c core.fsmonitor=false status). A class that keeps returning after being closed needs a check outside the agent's startup code — behavior at the OS boundary. The signal is: a git status in a freshly-opened repository spawned an outbound network call, wrote to ~/.ssh/, or forked a shell reading /etc/passwd. No benign explanation for a background "figure out what branch we're on" operation. Stop it at the syscall — not at a prompt the user never saw because the exploit ran first.

Sources


SPR{K3 is a security research operation that pairs offensive vulnerability research with runtime behavioral defense. Defend is our runtime agent. To talk about a deployment, reach us at support@sprk3.com.