Don't run code from a repository you don't trust.

But AI coding agents are creating a slightly different security problem.

Sometimes, you don't need to manually run the malicious code.

Your coding agent may interact with the repository for you.

And that means a repository is no longer just a collection of source files.

It can also contain instructions, scripts, configuration, and agent-specific files that influence what your AI assistant does.

Imagine this workflow:

You clone a repository
        ↓
Open it with an AI coding agent
        ↓
Agent starts understanding the project
        ↓
Agent reads instructions and configuration
        ↓
Agent runs Git or other tools
        ↓
Malicious repository influences that behavior