Malicious hooks and skills get most of the attention when we talk about attacks against coding agents. Attackers have other options. In this article, we cover two ways a trusted project can execute code before the first prompt. securitylabs.datadoghq.com/articles/cod...
Before the first prompt: Code execution paths in trusted coding-agent projects | Datadog Security Labs
Learn how trusted coding-agent projects can execute repository-controlled code before the first prompt through Codex MCP configuration and Claude Code environment settings.
securitylabs.datadoghq.com