The Guardrails
A repo you only opened can run code through your AI coding agent
Two security stories worth your attention this morning, and neither is interesting for the reason the headlines suggest: both are about inputs we taught agents to treat as harmless. One is a git setting nobody audits. The other is the internet itself. Opening a suspicious folder is now enough to