Agents trust the directory you point them at. That is the whole problem — and the whole fix.
Decide what the directory is allowed to say before the agent reads it. None of this depends on a vendor patch, and none of it names an unpatched product.
pip install agent-boundary-scan && abs ./that-repo
— git config sinks, filter drivers, repo-declared MCP servers, agent hooks,
GIT_* env channels, devcontainer lifecycle commands, escaping symlinks.git clone does not carry:
git -C ./that-repo config --local --list. Anything under
core.fsmonitor, core.hooksPath, core.pager,
core.editor, core.sshCommand, diff.external,
filter.*, protocol.* is a program the repository chose..gitattributes. filter=<name> and
diff=<name> name drivers whose program comes from that config. It is
content; it does not need to be committed to apply..git/hooks, and at core.hooksPath. Hooks
inside the repository are ordinary files git will execute.mss ~/.config/claude and mss ./some-server --source-only.npx -y), point path arguments at one project directory instead of /,
drop --privileged and docker.sock, use https, keep credentials out of
a file that syncs..mcp.json in a repo, no .claude/settings.json with hooks, no
.aider.conf.yml with lint-cmd, no unreviewed
.devcontainer lifecycle command.abs . --fail-on high,
mss . --fail-on high. Fast, offline, no credentials.That you will sometimes be handed a repository you did not write: a template, an archive, a customer's tree, a shared folder, a PR checkout. In those cases the repository's configuration is input — and everything above is about not treating input as instruction.