🤖 Before the first prompt: Code execution paths in trusted coding-agent projects
Trusted coding-agent projects can execute repository-controlled code before the first user prompt via MCP server configs or PATH hijacking in .claude/settings.json. Developers should treat project trust like running an arbitrary setup script.
https://securitylabs.datadoghq.com/articles/coding-agent-project-trust-code-execution-before-first-prompt
#AI
Post #1527
388

- ❤ 1
- 👍 1
- 🔥 1