SD-027 — Nested Bare Git Execution Config
SD-027 flags command-valued core.fsmonitor or diff.external declarations in supported nested bare Git configuration without running Git or the configured command.
What it matches
A nonempty command-valued core.fsmonitor or diff.external in a bounded nested bare Git directory with regular HEAD and config files, an objects directory and core.bare=true.
Why it matters
If an affected agent automatically discovers this bare repository and invokes Git with the executable setting, repository-controlled commands may run with that process's privileges. Static inventory cannot establish discovery, invocation or exposure to CVE-2026-45033. Unsupported configuration fails without a grade; symlink markers in complete inspected GitHub trees fail closed, but tarball-only scans may omit them.
Example
gitconfig
# nested.git/config (illustrative only)
[core]
bare = true
fsmonitor = /path/to/approved-monitorThe configured monitor is a command; this declaration alone does not mean an agent will run it.
How to fix it
Remove executable Git settings from untrusted nested repositories. Upgrade affected Copilot CLI to 1.0.43 or later and prevent automatic bare-repository discovery; verify the actual runtime before treating a declaration as an executed command.
Known false positives
A legitimate Git integration in a nested bare repository that the agent never discovers or executes. A declaration does not establish the effective runtime or an affected agent version.
Standards mapping
OWASP ASI ASI05
CWE CWE-78
Check your own skills
Scan a repository or a single skill against this rule and the rest of the catalogue, free.