SD-027 — Nested Bare Git Execution Config

SD-027 flags command-valued core.fsmonitor or diff.external declarations in supported nested bare Git configuration without running Git or the configured command.

What it matches

A nonempty command-valued core.fsmonitor or diff.external in a bounded nested bare Git directory with regular HEAD and config files, an objects directory and core.bare=true.

Why it matters

If an affected agent automatically discovers this bare repository and invokes Git with the executable setting, repository-controlled commands may run with that process's privileges. Static inventory cannot establish discovery, invocation or exposure to CVE-2026-45033. Unsupported configuration fails without a grade; symlink markers in complete inspected GitHub trees fail closed, but tarball-only scans may omit them.

Example

gitconfig

# nested.git/config (illustrative only)
[core]
    bare = true
    fsmonitor = /path/to/approved-monitor

The configured monitor is a command; this declaration alone does not mean an agent will run it.

How to fix it

Remove executable Git settings from untrusted nested repositories. Upgrade affected Copilot CLI to 1.0.43 or later and prevent automatic bare-repository discovery; verify the actual runtime before treating a declaration as an executed command.

Known false positives

A legitimate Git integration in a nested bare repository that the agent never discovers or executes. A declaration does not establish the effective runtime or an affected agent version.

Standards mapping

OWASP ASI ASI05

CWE CWE-78

Check your own skills

Scan a repository or a single skill against this rule and the rest of the catalogue, free.