Before the first prompt: Code execution paths in trusted coding-agent projects
ID: 5fa49250-ad1b-5a95-8a98-fa4beff66a91
STIX ID: report--5fa49250-ad1b-5a95-8a98-fa4beff66a91
Feed Name: Datadog Security Labs
This research post shows that trusting a repository in modern coding agents can let attacker-controlled code run before the first prompt by abusing project configurations (MCP servers), environment variables (PATH), hooks, editor/task settings, and runtime startup files; it provides PoCs, cites real-world campaigns, and recommends treating project trust like running code (use disposable environments, monitor agent-related processes, and inspect various config and startup vectors).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
