Key takeaways
- Hooks, MCP entries, folder-open tasks and always-on rules in a repository can run code when it is opened.
- Mini Shai-Hulud and Miasma committed Claude Code, Gemini CLI and Cursor config to repositories in 2026.
- In CI, claude -p and Agent SDK runs skip the trust dialog, so repository hooks run.
- Cursor ships with workspace trust off. Gemini CLI has had folder trust on by default since February 2026.
- Give agent config paths code owners, and flag added hooks, MCP servers and hidden characters in CI.
Claude Code security now starts with the files in the repository. A committed .claude/settings.json can run shell commands when a session starts, .mcp.json launches server processes, and Cursor rules and AGENTS.md tell the agent what to do, including which commands to run. Attackers used these files throughout 2026. The Mini Shai-Hulud worm committed a Claude Code start-up hook to every repository a stolen GitHub token could write to.1 In June a single Miasma commit added start-up hooks for Claude Code and Gemini CLI, an always-on Cursor rule and a VS Code folder-open task to a Microsoft repository.2
Treat these paths as code. OWASP’s GenAI Security Project published its review of the third quarter on 8 October 2026. It tells teams to review AI coding-agent configuration files as executable supply-chain artefacts, and warns that opening a cloned repository in an AI coding tool can run code without any installation step.3 In practice that means code owners for the paths, pinned MCP servers, deny-by-default permissions, isolation for code you didn’t write and a CI check that flags new hooks and MCP entries.
This post lists the files Claude Code, Cursor, Gemini CLI and Codex read and what each can make them do, the campaigns and CVEs that used them, and what each tool’s trust prompt covers. It ends with a CI sketch and a checklist. Sources are public and dated on or before 9 October 2026. Our post on AI agent containment lessons covered lab incidents and runtime controls; this one is about repository files and developer machines.
Which files coding agents read, and what each can do
Instruction files and configuration files reach your machine by different routes. An instruction file, such as AGENTS.md, CLAUDE.md or a Cursor rule, goes into the model’s context, and the model then acts through whatever tools it is allowed to use. A configuration file is executed by the tool itself. Claude Code’s own documentation draws the same line: settings files are enforced whether Claude follows them or not, and CLAUDE.md is read as guidance.45
The main paths, as of 9 October 2026:
| Path | Read by | When it loads | What it can make happen |
|---|---|---|---|
AGENTS.md, root and nested |
Codex, Cursor, Copilot; Claude Code when there is no CLAUDE.md; Gemini CLI if configured |
Session start, nested files as the agent works | Instructions, including checks to run before finishing |
CLAUDE.md, .claude/rules/ |
Claude Code | Session start, subfolders on demand | Instructions, and @ imports of other files |
.claude/settings.json |
Claude Code; Cursor imports its hooks | Session start, reloaded on change | Hooks that run shell commands, env values, helper commands, permission rules |
.mcp.json |
Claude Code | Session start, after approval | Starts server processes or connects to remote URLs |
.claude/skills/*/SKILL.md |
Claude Code; Cursor imports third-party skills | When you or Claude invoke it | Runs ! shell lines; pre-approves tools through allowed-tools |
.cursor/rules/*.mdc |
Cursor | Every chat if alwaysApply: true |
Instructions |
.cursor/mcp.json, .cursor/hooks.json |
Cursor editor and CLI | After approval; hooks in a trusted workspace | Server processes and hook commands |
GEMINI.md, .gemini/settings.json |
Gemini CLI | Session start in a trusted folder | Instructions; hooks, MCP servers and auto-approved tools |
.codex/config.toml, .codex/hooks.json |
Codex | Trusted projects only | Settings and hooks |
.vscode/tasks.json |
VS Code, Cursor | Folder open, if a task sets runOn: folderOpen |
Any shell command |
.github/copilot-instructions.md |
GitHub Copilot | Every request in the repository | Instructions |
Sources are each vendor’s documentation, and StepSecurity for the VS Code task.456789101112132
Markdown instruction files can still start commands. The AGENTS.md FAQ says an agent will try to run the programmatic checks a file lists and fix failures before it finishes, and the site says over 60,000 open-source projects use the format.14 For AGENTS.md security, read every line as something the agent may act on. Miasma’s Cursor rule was a short Markdown file that told the agent to run the payload as a setup step.2
Files also cross between tools. Cursor loads hooks from Claude Code’s .claude/settings.json and .claude/settings.local.json through a third-party import setting that is on by default, and it maps Claude’s SessionStart event to its own.9 GitHub Copilot accepts a root CLAUDE.md or GEMINI.md as agent instructions.13 A team that has standardised on one agent still has to guard the other agents’ paths. Our comparison of Claude Code, Codex and Cursor found that all three, and Pi, read AGENTS.md, so one file now steers most of a mixed team’s agents.
The 2026 AI coding agent supply chain attacks
These are the public cases from 2026 in which attackers used agent configuration files, as of 9 October:
| Date | Campaign | Agent files involved | How they arrived |
|---|---|---|---|
| 29 April 2026 | Mini Shai-Hulud, SAP-related npm packages151 | .claude/settings.json SessionStart hook matching every session; .vscode/tasks.json folder-open task |
Committed with stolen GitHub tokens as “chore: update dependencies”, under an author named claude |
| 10 to 12 May 2026 | Mini Shai-Hulud, TanStack wave316 | A Claude Code hook and a VS Code task that stayed after the package was uninstalled | 84 malicious versions of 42 TanStack packages, published with an OIDC token taken from CI |
| 5 June 2026 | Miasma2 | SessionStart hooks in .claude/settings.json and .gemini/settings.json; .cursor/rules/setup.mdc with alwaysApply: true; .vscode/tasks.json |
One commit to Azure/durabletask from a compromised contributor account; GitHub disabled 73 repositories that day |
| 10 August 2026 | Deadbugz17 | MCP configuration: 17 remote endpoints, 4 entries running a hidden local Python file | 23 pull requests from one account in 74 minutes; none merged |
| 28 August 2026 | Mini Shai-Hulud, openapi-react-query-codegen18 | .claude/settings.json SessionStart hook, .gemini/settings.json, .vscode/tasks.json, Cursor rule files |
Trojanised npm releases, now also spreading to RubyGems and PyPI |
In the April, June and August waves the files arrived as git commits, so they reached every clone and outlived the package that planted them. The hooks used SessionStart, which fires before the developer types anything, and StepSecurity notes that the April hook’s matcher made it fire for every session whatever the task.15 For Miasma, StepSecurity says cloning the repository was safe and that opening it in any of the four tools ran the payload.2 The April and May commits both carried a forged author named claude, and TanStack’s post-mortem points out that the name had nothing to do with Anthropic.16
StepSecurity also reports that the April payload fetched up to 50 branches per repository and filtered them by branch protection rules before pushing.15 Branch protection that requires a reviewed pull request is the control a stolen developer token runs into, and it should cover every long-lived branch.
Deadbugz came in through the front door instead. One account opened 23 pull requests against AI and developer-tool projects on 10 August, most adding a remote MCP endpoint to the project’s configuration in what Pillar Security describes as a routine-looking change.17 None was merged. The server behaved normally for three tool calls and then changed its tool descriptions to send agents after SSH keys and cloud credentials. The containment post linked above covers that half of the attack.
Advisories where repository config ran code
Vendors have patched a steady run of bugs in which repository files ran before, or around, a trust prompt. These are the published advisories we found for Claude Code, Cursor and Gemini CLI that involve files a repository or an agent can write, as of 9 October 2026.
| Tool | Advisory | Fixed in | What the repository or agent supplied, and the effect |
|---|---|---|---|
| Claude Code | CVE-2025-59536, October 2025 | 1.0.111 | Repository settings approved its own .mcp.json servers, which started before the trust dialog |
| Claude Code | CVE-2025-65099, November 2025 | 1.0.39 | Yarn config (plugins, yarnPath) ran through yarn --version before trust |
| Claude Code | CVE-2026-21852, January 2026 | 2.0.65 | ANTHROPIC_BASE_URL in repository settings sent API requests, with the user’s key, before trust |
| Claude Code | CVE-2026-25725, February 2026 | 2.1.2 | Code in the sandbox created .claude/settings.json; its SessionStart hook ran on the host at restart |
| Claude Code | CVE-2026-33068, March 2026 | 2.1.53 | defaultMode: bypassPermissions in repository settings skipped the trust dialog |
| Claude Code | CVE-2026-40068, April 2026 | 2.1.84 | A git worktree commondir file pointing at a trusted path skipped the dialog, and hooks ran |
| Cursor | CVE-2025-54136, August 2025 | 1.3 | An approved MCP entry, edited in a shared repository, ran its new command without re-approval |
| Cursor | CVE-2025-54135, August 2025 | 1.3.9 | An agent steered by prompt injection created .cursor/mcp.json, and the new server ran without approval |
| Cursor CLI | CVE-2025-61592, October 2025 | 2025.09.17 build | A project .cursor/cli.json allowed shell commands, and injection through rule files led to code execution |
| Cursor CLI | CVE-2025-64109, November 2025 | 2025.09.17 build | .cursor/mcp.json in a cloned repository ran its command without warning |
| Cursor | CVE-2026-26268, February 2026 | 2.5 | The agent wrote .git hooks that later ran outside the sandbox |
| Cursor | CVE-2026-48124, May 2026 | 3.0.0 | Claude hook commands in .claude/settings.local.json ran at the end of agent turns without approval |
| Gemini CLI | CVE-2026-12537, April 2026 | 0.39.1 | Headless runs trusted the workspace and its .gemini/ environment, and --yolo ignored allowlists |
Sources are the vendors’ advisories, plus Check Point Research for the detail of CVE-2025-59536.19202122
Most of the Claude Code fixes close gaps around the trust dialog, from settings read before it appeared to a crafted git file that borrowed trust from another folder. Several Cursor and Claude Code bugs run the other way: an agent, possibly steered by injected text, writes a config file that the tool later runs with fewer restrictions than the agent had. The Gemini CLI advisory, rated 10.0, is about CI and comes up again below.
An earlier Anthropic advisory, in September 2025, changed the dialog’s wording because it didn’t make clear that accepting it lets Claude Code run files in the folder without further confirmation.19 The dialog still works that way. It is one decision per repository, covering the hooks, environment values and helper commands in that repository’s settings.
Trust prompts in Claude Code, Cursor and Gemini CLI compared
Each tool now asks, or can ask, before it loads a repository’s configuration. They differ on defaults, on what happens when a trusted file changes, and on scripted runs. As of 9 October 2026:
| Claude Code | Cursor | Gemini CLI | |
|---|---|---|---|
| Trust prompt for a new folder | Yes, in interactive sessions | Supported, off by default | On by default since v0.28.0 |
| Held back until you trust | Hooks, most env values, allow rules; .mcp.json servers have their own prompt |
With trust on, restricted mode turns off AI features; project hooks need a trusted workspace | Workspace settings and hooks, .env, MCP servers, custom commands, skills, tool auto-approval |
| When a committed hook changes | The docs describe no new prompt; settings files reload on change | Workspace hook commands need approval since 3.0.0 | Treated as a new hook and announced before it runs |
| Scripted and CI runs | claude -p and SDK runs skip the dialog; hooks run and .mcp.json servers connect |
The CLI asks before enabling a project’s MCP servers | An untrusted folder exits with an error unless trust is forced |
Sources: Claude Code’s permissions, hooks and MCP docs,232425 Cursor’s security and hooks docs and advisories,26921 and Gemini CLI’s trusted-folders and hooks docs.2728
Cursor supports VS Code’s workspace trust but ships with it switched off. Its security page says restricted mode breaks the AI features and suggests a basic text editor for untrusted repositories.26 Oasis Security showed in September 2025 that, with trust off, a .vscode/tasks.json task set to run on folder open fired without a prompt. VS Code itself enables workspace trust by default and disables agents in restricted mode.2930 Cursor lets agents edit workspace files without approval except configuration files, asks before every MCP connection and, since version 1.3, asks again when an MCP entry changes. Cursor describes its terminal run modes, which range from an allowlist to a classifier, as best-effort guardrails.2621
Cursor rules are an established prompt injection channel. A rule with alwaysApply: true goes into every chat.7 Pillar Security’s Rules File Backdoor research in March 2025 hid instructions in rule files with zero-width joiners and bidirectional text markers, which at the time were also invisible in GitHub’s pull request view. Cursor’s response was that the risk falls on users, and GitHub added a warning for hidden Unicode text on 1 May 2025.3132 Cursor’s own rules page says AI guidance shouldn’t be your only security control.7
Gemini CLI switched folder trust on by default in v0.28.0, released on 10 February 2026, although its trusted-folders page still describes the feature as disabled by default. Check security.folderTrust.enabled in your own settings.3327 In an untrusted folder it ignores workspace settings and .env files, connects no MCP servers and loads no custom commands, project hooks or skills. It fingerprints project hooks, and a hook whose name or command changes, for example after a git pull, is treated as new and announced before it runs.28 Two keys deserve a look in review. trust: true on an MCP server skips every confirmation for its tools, and tools.allowed lists tools that skip the confirmation dialog.11
Codex goes furthest on the row that matters most. Trust prompts are built for a repository you open for the first time, while Mini Shai-Hulud and Miasma committed to repositories their victims already worked in and had most likely trusted long before. Codex loads a project’s .codex/ layer only when you trust the project, and it records trust against each hook’s hash, so a new or edited hook is skipped until someone reviews it in /hooks.12 Claude Code’s documentation describes trust as one decision per repository and says settings files reload when they change. It doesn’t describe a second prompt when a pulled commit adds or edits a hook.2324
Claude Code security settings for repositories you didn’t write
Claude Code asks once per repository, so later changes to a repository’s hooks have to be caught in code review. In an interactive session, Claude Code shows the workspace trust dialog the first time you start it in a repository, keyed to the git root. Until you accept, it holds back hooks from every settings file, most env values and the repository’s allow rules. Deny and ask rules apply at once, because they only restrict.2324 Servers in .mcp.json get a separate approval prompt, and a cloned repository can no longer approve its own servers through enableAllProjectMcpServers.25 Project settings also can’t set the starting mode to auto or bypassPermissions.34 Accepting the dialog is the decision that matters, so read .claude/settings.json, .mcp.json and .claude/skills/ first.
Skills deserve the same reading. A ! line in a SKILL.md runs a shell command before the skill’s text reaches Claude, without a prompt, as long as your permission rules or the skill’s own allowed-tools allow it. Workspace trust never gates allowed-tools, and Anthropic’s docs warn that a skill can grant itself broad tool access.6
Since v2.1.283, interactive terminal and VS Code sessions start in auto mode, where a classifier model reviews actions in place of you. Manual mode asks before edits and commands, and dontAsk denies anything that would prompt, which suits CI. Anthropic says bypassPermissions belongs only in isolated containers and VMs.35
In every mode except bypass, Claude Code never auto-approves writes to a list of protected paths, including .claude/, .git, .vscode, .devcontainer, .mcp.json and shell profiles.35 The list doesn’t include .cursor/ or .gemini/. In acceptEdits or auto mode, a session steered by injected text could write a Cursor rule or a Gemini CLI hook without a prompt, ready for whoever next opens the repository in that tool. If your team uses more than one agent, add Edit deny rules for those paths yourself.
For a team, put the strict parts in managed settings, which a repository can’t override. This is a strict starting point:
{
"allowManagedHooksOnly": true,
"allowManagedPermissionRulesOnly": true,
"disableSkillShellExecution": true,
"allowManagedMcpServersOnly": true,
"allowedMcpServers": [
{ "serverCommand": ["uvx", "--from", "docs-mcp==2.4.1", "docs-mcp"] },
{ "serverUrl": "https://mcp.example.com/*" }
],
"permissions": {
"disableBypassPermissionsMode": "disable",
"deny": ["Read(.env)", "Read(.env.*)", "Read(~/.ssh/**)", "Read(~/.aws/**)",
"Edit(.cursor/**)", "Edit(.gemini/**)"]
}
}
allowManagedHooksOnly blocks user, project, local and plugin hooks. allowManagedPermissionRulesOnly ignores allow rules from other scopes and, from v2.1.282, the allowed-tools of project skills. disableSkillShellExecution replaces each ! line in a skill with a placeholder, and the MCP keys are covered below.24634 Read deny rules cover Claude’s file tools, so turn on the Bash sandbox if you want the same limits enforced for shell commands.36
Agents in CI read the pull request’s config
An agent that runs in CI on a pull request reads the pull request’s files. Claude Code’s claude -p and Agent SDK sessions never show the trust dialog and treat the folder as trusted. Hooks committed in the repository’s .claude/settings.json run, its env block applies and its .mcp.json servers connect without asking.2324 Anthropic gives three options for a repository you didn’t write. --setting-sources user reads neither the project’s settings files nor its .mcp.json. --bare skips the project’s hooks, skills, subagents, plugins and MCP servers, but still applies its env block. --settings '{"disableAllHooks": true}' turns hooks off for the run; the same key in your user settings isn’t enough, because project settings rank above yours and can switch hooks back on.23 Passing the first two together keeps the project’s settings, env block, hooks, skills and MCP servers out of the run.
Gemini CLI fixed the same class of problem in April. Before 0.39.1, headless runs trusted the workspace automatically when loading configuration and environment variables, and --yolo ignored tool allowlists. Either could lead to code execution in CI, including through the run-gemini-cli GitHub Action before its 0.1.22 release, and the advisory rates the issue 10.0.22 A headless run in an untrusted folder now exits with an error unless you pass --skip-trust or set GEMINI_CLI_TRUST_WORKSPACE=true, so keep both out of jobs that handle outside contributions.27
GitHub Copilot code review reads custom instructions, agent instructions and skills from the pull request’s head branch, so the change under review supplies the reviewer’s instructions.13
The TanStack compromise began with a pull_request_target workflow that ran code from a fork.16 For agent jobs on outside pull requests, use pull_request, give the job no secrets and a read-only token, and load configuration from the base branch.
MCP config security: pin servers and re-approve changes
An MCP entry is a command line or a URL. A stdio entry in .mcp.json, .cursor/mcp.json or .gemini/settings.json names a program, its arguments and its environment, and that program runs with your user’s access. The common npx -y package-name form names no version, so what runs is whatever version npm resolves on that machine, which could be a compromised release. Pin an exact version, install it through a lockfile or container image where you can, and change it only in a reviewed pull request.
On Claude Code, a managed allowlist turns the pin into policy. serverCommand entries match the exact command and arguments, so an entry that includes the version blocks every other version, and serverUrl entries limit remote servers to hosts you name. Set allowManagedMcpServersOnly so users can’t widen the list. Don’t rely on serverName entries, which Anthropic’s docs say are not a security control because anyone can give any server an approved name.37
Remote servers can’t be pinned this way, because the code behind the URL can change at any time. Deadbugz changed its tool descriptions after the third call, so record a fingerprint of each server’s tool definitions when you approve it and require re-approval when it changes. The containment post has a short implementation. Cursor already asks again when an mcpServers entry changes.21 Claude Code reads credential variables as empty in a remote server’s URL and headers, so a project’s .mcp.json can’t forward your Claude Code or cloud credentials to the server it names.25
A CI check that flags agent config changes
Start with ownership. Put this block at the end of CODEOWNERS, because the last matching pattern wins, and give the CODEOWNERS file an owner too. Then turn on “Require review from Code Owners” in branch protection or a ruleset for every long-lived branch.38
# Agent and editor configuration. Keep this block last.
AGENTS.md @your-org/agent-config-owners
CLAUDE.md @your-org/agent-config-owners
GEMINI.md @your-org/agent-config-owners
.mcp.json @your-org/agent-config-owners
.claude/ @your-org/agent-config-owners
.cursor/ @your-org/agent-config-owners
.gemini/ @your-org/agent-config-owners
.codex/ @your-org/agent-config-owners
.vscode/ @your-org/agent-config-owners
.devcontainer/ @your-org/agent-config-owners
/.github/ @your-org/agent-config-owners
Then add a check that makes each change visible. This GitHub Actions job runs on pull_request, which gives pull requests from forks no secrets and a read-only token. It warns on every changed file under those paths. It fails when an added line brings in a hook, an MCP server, a task, an always-on rule or a permission change, or when a file contains zero-width, bidirectional-control or tag characters.
name: agent-config
on: pull_request
permissions:
contents: read
jobs:
scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
persist-credentials: false
- name: Flag agent config changes
env:
BASE_REF: ${{ github.base_ref }}
run: |
paths='(^|/)(AGENTS|CLAUDE|GEMINI)\.md$|(^|/)\.mcp\.json$|(^|/)\.(claude|cursor|gemini|codex|vscode|devcontainer)/|^\.github/'
risky='"hooks"|mcp(json)?servers|"command"|"url"|"env"|runon|alwaysapply|allowed-tools|"allow"|defaultmode|apikeyhelper|base_url|"trust"'
files=$(git diff --name-only --diff-filter=d "origin/$BASE_REF...HEAD" | grep -E "$paths" || true)
[ -z "$files" ] && exit 0
status=0
for f in $files; do echo "::warning file=$f::Agent config changed. A code owner should review it."; done
if git diff "origin/$BASE_REF...HEAD" -- $files | grep -E '^\+[^+]' | grep -iE "$risky"; then
echo "::error::Adds hooks, MCP servers, tasks, rules or permissions"; status=1
fi
# Zero-width, bidi-control and tag characters hide text from reviewers
perl -CSD -ne '
if (/[\x{200B}-\x{200F}\x{202A}-\x{202E}\x{2060}-\x{2064}\x{2066}-\x{2069}\x{FEFF}\x{E0000}-\x{E007F}]/) {
print "::error file=$ARGV,line=$.::Invisible characters\n"; $bad = 1 }
close ARGV if eof; END { exit $bad }' $files || status=1
exit $status
A pull request can edit this workflow, and on pull_request the edited version is what runs, which is why /.github/ sits in the code-owners block. The pattern match doesn’t parse JSON or judge intent, and it will flag some harmless changes. Keep the check visible but optional, and let the code-owner rule decide who approves.
If you opened an affected repository
StepSecurity’s guidance for anyone who opened an affected repository in VS Code, Claude Code, Cursor or Gemini CLI after 2 June is to treat the machine as compromised.2 Combined with Snyk’s ordering advice, the response looks like this:39
- Disconnect the machine or CI runner from networks that hold secrets.
- Search your repositories and home directory for unexpected
.claude/,.gemini/,.cursor/or.vscode/tasks.jsonfiles, and for scripts they call, such as.github/setup.js. - Remove the hooks, tasks and rules before rotating anything.
- Rotate GitHub, npm, PyPI, SSH, cloud and Kubernetes credentials that the machine could reach, including roles a CI runner can assume.
- Check your packages for versions that have no matching tag or CI run, which StepSecurity suggests as a signal of an unauthorised publish.
- Pin GitHub Actions to commit SHAs so a replaced tag can’t change what runs.
Checklist before an agent opens a repository
- Own the paths. Code owners for agent and editor configuration, required code-owner review on every long-lived branch, and an owner for
CODEOWNERSitself. - Update the agents. The fixes above need at least Claude Code 2.1.84, Cursor 3.0.0 and Gemini CLI 0.39.1. Check the versions pinned in CI images and dev containers too.
- Switch trust on. Enable Cursor’s workspace trust, by MDM across a fleet. Confirm
security.folderTrust.enabledin Gemini CLI. Read.claude/,.mcp.jsonand the skills folder before accepting Claude Code’s dialog. - Deny by default. Managed settings for hooks, allow rules and MCP servers; deny reads of
.envfiles,~/.sshand cloud credential folders;bypassPermissionsand--yoloonly on isolated machines. - Pin MCP servers. Exact versions in every entry, exact-command allowlists, and fingerprints of remote tool definitions with re-approval when they change.
- Isolate code you didn’t write. Open it in a disposable VM or container that holds no credentials and has limited egress, built from your own definition. A repository’s
devcontainer.jsoncan run itsinitializeCommandon the host during initialisation.40 Anthropic’s dev container docs warn that, run with--dangerously-skip-permissions, a container won’t stop a malicious project from taking whatever is inside it, Claude Code’s credentials included.41 - Keep secrets out of reach. Don’t mount
~/.sshor cloud credential files into agent containers, prefer short-lived repository-scoped tokens, and keep long-lived tokens out of the shell environment an agent inherits.41 - Lock down CI.
pull_requestwith no secrets for outside contributions,--setting-sources userwith--bareand--permission-mode dontAskforclaude -p, no--skip-trustfor Gemini CLI, and configuration from the base branch. - Scan every pull request. Flag added hooks, MCP entries, folder-open tasks, always-on rules, permission changes and invisible characters, as the job above does.
- If a worm reached you, remove persistence first. Snyk advises clearing planted hooks from agent and editor config before rotating credentials.1 Search repositories for
SessionStarthooks and folder-open tasks, rungit log --all --author=claude@usersfor forged commits, then rotate everything the machine could reach.15
-
Snyk, “A Mini Shai-Hulud has Appeared: Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages”, 29 April 2026, https://snyk.io/blog/bun-based-stealer-hits-sap-cap-js-mbt-npm-packages/ ↩↩↩
-
StepSecurity, “Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents”, 5 June 2026, https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents ↩↩↩↩↩↩
-
OWASP GenAI Security Project, “GenAI and Agentic AI Exploit Roundup Q3 2026”, 8 October 2026, https://genai.owasp.org/2026/10/08/genai-and-agentic-ai-exploit-roundup-q3-2026 ↩↩
-
Anthropic, “Explore the .claude directory”, Claude Code docs, https://code.claude.com/docs/en/claude-directory ↩↩
-
Anthropic, “How Claude remembers your project”, Claude Code docs, https://code.claude.com/docs/en/memory ↩↩
-
Anthropic, Claude Code docs on skills, including dynamic context injection and allowed-tools, https://code.claude.com/docs/en/skills ↩↩↩
-
Cursor docs, “Rules”, https://cursor.com/docs/rules ↩↩↩
-
Cursor docs, “Model Context Protocol (MCP)”, https://cursor.com/docs/mcp ↩
-
Cursor docs, “Hooks” and “Third-party hooks”, https://cursor.com/docs/hooks and https://cursor.com/docs/reference/third-party-hooks ↩↩↩
-
Gemini CLI docs, “GEMINI.md”, https://geminicli.com/docs/cli/gemini-md/ ↩
-
Gemini CLI docs, “Configuration”, https://geminicli.com/docs/reference/configuration/ ↩↩
-
OpenAI, Codex docs, “Hooks” and “Config basics”, https://learn.chatgpt.com/docs/hooks and https://learn.chatgpt.com/docs/config-file/config-basic ↩↩
-
GitHub Docs, “Adding repository custom instructions for GitHub Copilot”, https://docs.github.com/en/copilot/how-tos/configure-custom-instructions/add-repository-instructions ↩↩↩
-
AGENTS.md, https://agents.md/ ↩
-
StepSecurity, “A Mini Shai-Hulud Has Appeared: Obfuscated Bun Runtime Payloads Hit SAP-Related npm Packages”, 29 April 2026, https://www.stepsecurity.io/blog/a-mini-shai-hulud-has-appeared ↩↩↩↩
-
TanStack, “npm supply chain compromise postmortem”, 11 May 2026, https://tanstack.com/blog/npm-supply-chain-compromise-postmortem ↩↩↩
-
Pillar Security, “Deadbugz: Currently Active MCP Supply-Chain Campaign”, 12 August 2026, https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain-campaign ↩↩
-
Endor Labs, “Mini Shai-Hulud worm hits openapi-react-query-codegen, spreads across npm, RubyGems, and PyPI”, 28 August 2026, https://www.endorlabs.com/learn/trojanized-7nohe-openapi-react-query-codegen-adds-pypi-to-a-self-replicating-npm-worm ↩
-
Anthropic, claude-code security advisories GHSA-ph6w-f82w-28w6, GHSA-4fgq-fpq9-mr3g, GHSA-5hhx-v7f6-x7gv, GHSA-jh7p-qr78-84p7, GHSA-ff64-7w26-62rf, GHSA-mmgp-wc2j-qcv7 and GHSA-q5hj-mxqh-vv77, September 2025 to April 2026, https://github.com/anthropics/claude-code/security/advisories ↩↩
-
Check Point Research, “Caught in the Hook: RCE and API Token Exfiltration Through Claude Code Project Files”, 25 February 2026, https://research.checkpoint.com/2026/rce-and-api-token-exfiltration-through-claude-code-project-files-cve-2025-59536/ ↩
-
Cursor security advisories GHSA-24mc-g4xr-4395, GHSA-4cxx-hrm3-49rm, GHSA-v64q-396f-7m79, GHSA-4hwr-97q3-37w2, GHSA-8pcm-8jpx-hv8r and GHSA-pc9j-3qc2-95wv, August 2025 to May 2026, https://github.com/cursor/cursor/security/advisories ↩↩↩↩
-
GitHub Advisory Database, “Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses”, GHSA-wpqr-6v78-jr5g, CVE-2026-12537, 24 April 2026, https://github.com/advisories/GHSA-wpqr-6v78-jr5g ↩↩
-
Anthropic, “Configure permissions”, Claude Code docs, sections on workspace trust and what runs before you trust a folder, https://code.claude.com/docs/en/permissions ↩↩↩↩↩
-
Anthropic, “Hooks reference”, Claude Code docs, including security considerations and workspace trust, https://code.claude.com/docs/en/hooks ↩↩↩↩↩
-
Anthropic, “Connect Claude Code to tools via MCP”, Claude Code docs, project scope and environment variable expansion, https://code.claude.com/docs/en/mcp ↩↩↩
-
Cursor docs, “Agent security”, https://cursor.com/docs/agent/security ↩↩↩
-
Gemini CLI docs, “Trusted Folders”, https://geminicli.com/docs/cli/trusted-folders/ ↩↩↩
-
Gemini CLI docs, “Hooks”, https://geminicli.com/docs/hooks/ ↩↩
-
Oasis Security, “Cursor ‘Open-Folder’ Autorun Lets Repos Run Code Without Consent”, https://www.oasis.security/resources/cursor-workspace-trust-vulnerability, reported by CSO Online on 10 September 2025, https://www.csoonline.com/article/4054796/cursors-autorun-lets-hackers-execute-arbitrary-code.html ↩
-
Visual Studio Code docs, “Workspace Trust”, https://code.visualstudio.com/docs/editing/workspaces/workspace-trust ↩
-
Pillar Security, “New Vulnerability in GitHub Copilot and Cursor: How Hackers Can Weaponize Code Agents”, 18 March 2025, https://www.pillar.security/blog/new-vulnerability-in-github-copilot-and-cursor-how-hackers-can-weaponize-code-agents ↩
-
GitHub Changelog, “GitHub now provides a warning about hidden Unicode text”, 1 May 2025, https://github.blog/changelog/2025-05-01-github-now-provides-a-warning-about-hidden-unicode-text/ ↩
-
google-gemini/gemini-cli, settings schema at v0.27.0 and v0.28.0, release v0.28.0 of 10 February 2026, https://github.com/google-gemini/gemini-cli/releases/tag/v0.28.0, and pull request 17596, https://github.com/google-gemini/gemini-cli/pull/17596 ↩
-
Anthropic, “Settings files and precedence”, Claude Code docs, https://code.claude.com/docs/en/settings ↩↩
-
Anthropic, “Choose a permission mode”, Claude Code docs, including protected paths, https://code.claude.com/docs/en/permission-modes ↩↩
-
Anthropic, “Security”, Claude Code docs, https://code.claude.com/docs/en/security ↩
-
Anthropic, “Control MCP server access for your organization”, Claude Code docs, https://code.claude.com/docs/en/managed-mcp ↩
-
GitHub Docs, “About code owners”, https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/customizing-your-repository/about-code-owners ↩
-
Snyk, “Miasma supply chain attack: malicious code in @redhat-cloud-services npm packages”, 1 June 2026, https://snyk.io/blog/miasma-supply-chain-attack-malicious-code-redhat-cloud-services-npm-packages/ ↩
-
Development Containers specification, “devcontainer.json reference”, https://containers.dev/implementors/json_reference/ ↩
-
Anthropic, “Development containers”, Claude Code docs, https://code.claude.com/docs/en/devcontainer ↩↩
Frequently asked questions
Is Claude Code safe to use on an untrusted repository?
Only after you have read its configuration, and ideally on a machine that holds no credentials. In interactive sessions Claude Code holds back a repository’s hooks until you accept the trust dialog, but accepting lets them run without further prompts, and claude -p or Agent SDK runs skip the dialog entirely.
Is AGENTS.md a security risk?
AGENTS.md runs nothing by itself, but coding agents follow it, and the format’s own FAQ says agents will try to run the checks it lists before finishing a task. Treat a change to it like a code change, with an owner and a review.
Can Cursor rules be used for prompt injection?
Yes. A rule with alwaysApply set to true goes into every chat, and in June 2026 the Miasma worm planted one that told Cursor’s agent to run its payload as a setup step. Pillar Security showed in 2025 that invisible Unicode characters can hide instructions in rule files.
How do I secure MCP config files like .mcp.json?
Review changes to them in pull requests, pin exact package versions, and on Claude Code enforce a managed allowlist with exact serverCommand or serverUrl entries. Re-approve a server whenever its definition or its tool descriptions change.
What is an AI coding agent supply chain attack?
An attack that plants files a coding agent or its editor will act on, such as hooks, MCP server entries or rules, in a repository or package. In 2026 the Mini Shai-Hulud worm used stolen GitHub tokens to commit Claude Code SessionStart hooks to its victims’ repositories.
Does claude -p run hooks from the repository?
Yes. claude -p and Agent SDK sessions never show the trust dialog and treat the folder as trusted, so hooks in the repository’s .claude/settings.json run and its .mcp.json servers connect. Pass --setting-sources user with --bare when the repository isn’t yours.
Building something like this?
9io is a small team of senior engineers with a fractional CTO, and we work by the hour. Send us a note about your product. The reply comes from the person who'd do the work.