A coding agent treats your README and setup files as instructions, and a hostile repo can use that against you. On July 8, 2026, Wiz published its GhostApproval research, which found the same flaw in six mainstream coding assistants: Amazon Q Developer, Claude Code, Augment, Cursor, Google Antigravity, and Windsurf. A repo could steer each one into writing a file the user never meant to approve. Before we point an agent at a repo, we check five things: real file paths, a real approval gate, repo text treated as data, a throwaway identity, and a log of every write.
The trick runs on a symlink. A symlink (symbolic link) is a file that only points to another path, so a write to the symlink lands wherever it points.
1. Resolve the real path before anything is written. In Wiz's proof of concept, a symlink named project_settings.json pointed at ~/.ssh/authorized_keys. A routine "set up this project" request then planted the attacker's SSH key. In one tool, the agent's own reasoning noticed the link while the confirmation prompt still showed the harmless file name. We set up our tooling to resolve every path to its real target before a write. The file you approve on screen must be the file that changes.
2. Make the approval prompt a gate, not an undo button. That's Wiz's own recommendation. In their testing, one assistant wrote to disk before the accept and reject buttons appeared, so the prompt only asked whether to keep a change that had already happened. On every tool we hand to a client engineering team, nothing lands on disk until a person says yes.
3. Read the README and setup scripts as data. The attack works because the agent follows instructions it finds inside the repo it was just given. A fresh clone from a source you don't fully trust doesn't get to direct your agent. A "please update this file" note in a setup script gets a human look before anyone acts on it.
4. Run the agent under a throwaway identity. A session on a new repo shouldn't see your real ~/.ssh, your cloud credentials, or production systems. Then even a successful symlink write lands on nothing worth taking. On a small team, agent containment without a platform team shows how to set that up. Scoping a deployed agent's access is a separate job, with its own checklist for production credentials.
5. Log every write outside the expected files. When Wiz published, three of the six vendors had shipped fixes, two were still working on them, and one disputed the finding. You can't plan around a vendor's patch timeline. An audit trail catches the write that no fix covers yet.
Our rule from client work: give a coding agent the trust you'd give a script from a stranger, not the trust you give the developer who launched it. Most of the risk comes from skipping that decision, because the default is to inherit everything the developer can reach.
None of this needs new tooling. It needs you to treat an agent's workspace like any other process that can write to your machine. Our AI implementation reviews run these checks before an agent touches a client codebase. AI that ships, not AI that demos.

