Agent harness security and Git

· · Sept. 12, 2026, 2:34 p.m.
Summary
The blog post discusses security issues related to running Git commands in potentially malicious directory structures while exploring the interaction between Git and coding agents like Claude Code and Codex. The author presents their findings on how improperly configured repositories can lead to arbitrary code execution and emphasizes the importance of not running Git commands in untrusted directories. Additionally, they share their interactions with Git-related projects regarding these security vulnerabilities.
AUTHOR