Researchers reported that developer tooling can execute code from a project before a user writes code or starts a build, extending long-standing supply-chain concerns from package restore and project evaluation into newer coding-agent workflows. Datadog Security Labs described pre-prompt execution paths in trusted coding-agent projects, while separate research on NuGet and MSBuild showed that opening a repository or restoring dependencies can invoke .targets or .props logic and arbitrary commands through MSBuild's Exec task during project evaluation.
The combined findings highlight a risk path in which a cloned or otherwise trusted repository can trigger automation in IDEs, agents, or CI/CD environments and expose sensitive credentials, tokens, and build secrets. Researchers noted that Visual Studio applies Mark of the Web warnings to downloaded files but not necessarily to repositories obtained via git clone, leaving a gap where malicious project metadata or package content may run without equivalent trust prompts; community discussion emphasized isolating untrusted projects in disposable VMs or tightly scoped rootless containers as a baseline mitigation.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
The Tier Zero Security article states that the behavior allowing code execution through NuGet/MSBuild project logic was raised to the NuGet team as a security issue in 2020.
A post appeared in r/netsec linking to Datadog's article, and a commenter suggested using disposable VMs or rootless containers with only the untrusted folder mounted as a baseline mitigation for handling untrusted projects.
Datadog Security Labs published an article titled "Before the first prompt: Code execution paths in trusted coding-agent projects," describing code execution risks that can occur before a user prompt in trusted coding-agent projects.
According to the article, Microsoft Security Response Center concluded that opening or cloning a project is user-initiated and that resulting build logic execution is expected by design, ultimately determining it was not a vulnerability or security boundary bypass.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcesecuritylabs.datadoghq.com
Open sourcetierzerosecurity.co.nz
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.