Behavioral Risk Brief: Malicious .git Configs
Governance frameworks that treat workspace-trust prompts and sandboxing as sufficient protection create systemic risk when an agent’s own routine background operations bypass both entirely. Zero Trust for Code addresses this by requiring a pre-execution trust decision on every command a repository can trigger, not only the ones a user’s approval prompt was designed to catch. […]

