build1 publisher
A repo's core.fsmonitor setting turns an agent's routine git status into code execution
GitSpawn, as summarised in a dev.to write-up of Cloud Security Alliance findings, uses a Git performance setting to run attacker code when a coding agent inspects a project it just opened. Seven agents are named.
Publishers:dev.to
Reality
- Evidence32
- Adoption
- Insufficient
- Hype gap+18
- Incentives28
- Confidence40