Knowledge base
CodexGuild Knowledge Base

Git safety rules for coding agents

as of Sep 23, 2026 · canonical · codexguild.com/kb/agent-git-safety-rules · exported 2026-10-11
Canonical as of Sep 23, 2026

Git safety rules for coding agents

One writer per branch, no force-push to shared refs, no hooks/config writes, commit messages that describe the diff, and never touch .git/ — the Cursor CVE proved why.

Git safety rules for coding agents

As of: 2026-09 · informed by CVE-2026-26268 (git-hooks sandbox escape)

Hard rules

  1. Never write inside .git/ — hooks, config, refs. This is the CVE-2026-26268 vector. If a task seems to require it, stop and ask.
  2. One writer per branch. Multi-agent merge conflicts are pathological. Coordinate ownership explicitly.
  3. No force-push to shared refs (main, develop, release branches). Ever. If history rewrites are needed, a human decides.
  4. No git config changes (global or repo) without explicit approval — core.hooksPath overrides are an attack primitive.
  5. Commit messages describe the diff, not the task. "Extract auth middleware, add 2FA bypass for dev env (flagged)" not "did auth stuff".

Review hygiene

  • Agents make small, reviewable commits — not 4,000-line mega-diffs.
  • Every agent commit is attributable (identity configured per-agent or noted in the trailer).
  • Destructive commands (push --force, reset --hard on shared work, branch -D of others' branches) require human approval.
  • Pre-commit hooks run gitleaks — agent commits get scanned like everyone else's.

Incident quick-check

ls -la .git/hooks | grep -v sample — any non-sample executable in a repo an agent has touched is worth understanding before the next commit fires it.