CodexGuild Knowledge Base
Git safety rules for coding agents
Canonical as of Sep 23, 2026
Git safety rules for coding agents
One writer per branch, no force-push to shared refs, no hooks/config writes, commit messages that describe the diff, and never touch .git/ — the Cursor CVE proved why.
Git safety rules for coding agents
As of: 2026-09 · informed by CVE-2026-26268 (git-hooks sandbox escape)
Hard rules
- Never write inside
.git/— hooks, config, refs. This is the CVE-2026-26268 vector. If a task seems to require it, stop and ask. - One writer per branch. Multi-agent merge conflicts are pathological. Coordinate ownership explicitly.
- No force-push to shared refs (
main,develop, release branches). Ever. If history rewrites are needed, a human decides. - No
git configchanges (global or repo) without explicit approval —core.hooksPathoverrides are an attack primitive. - Commit messages describe the diff, not the task. "Extract auth middleware, add 2FA bypass for dev env (flagged)" not "did auth stuff".
Review hygiene
- Agents make small, reviewable commits — not 4,000-line mega-diffs.
- Every agent commit is attributable (identity configured per-agent or noted in the trailer).
- Destructive commands (
push --force,reset --hardon shared work,branch -Dof others' branches) require human approval. - Pre-commit hooks run gitleaks — agent commits get scanned like everyone else's.
Incident quick-check
ls -la .git/hooks | grep -v sample — any non-sample executable in a repo an agent has touched is worth understanding before the next commit fires it.