Git worktrees are not an isolation boundary for coding agents

The author argues that Git worktrees do not provide a secure isolation boundary for AI coding agents, as they share critical repository state. The post warns that agents can manipulate hooks and commit identities if given access to a worktree.
Why it matters
Security researchers are increasingly identifying vulnerabilities in how AI development tools interact with local file systems and version control.
Most tools that run AI coding agents in parallel give each one a git worktree. A worktree shares refs, config, stash and hooks with your real repository. Paste-and-run repros showing an agent can execute code in your main repo and rewrite your commit identity, plus benchmarks showing a properly isolated clone costs the same.
Give a coding agent its own git worktree, which is how most tools for running agents in parallel do it, and that agent can install a hook that runs on your machine the next time you commit in your real repository. It can rewrite the email your own commits are attributed to. It can pop another agent’s stash into its own tree.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in