Skip to content

Coding-agent CLI executes project-local hooks from a world-writable workspace or a world-writable ancestor of one

coding-agent-project-local-config-trust is a high severity check in the ai category, written in shell. Its source is templates/ai/coding-agent/coding-agent-project-local-config-trust.sh in cert-x-gen-templates.

Plants an identical benign project-local settings file in three workspaces that differ only in who may write the directory it sits in - a private 0700 checkout, a world-writable 0777 checkout, and a world-writable directory ABOVE an otherwise private checkout - and starts the coding-agent CLI in each. Honouring the private copy establishes the tool reads per-workspace settings at all; honouring either of the other two proves it runs hooks declared in a directory any local user could have written, or that its config search walks up out of the workspace it was pointed at into a shared one. Both are local privilege escalation into the agent (CVE-2026-35603 class, workspace edition).

Field Value
Id coding-agent-project-local-config-trust
Severity high
Language shell
Category ai
Author CERT-X-GEN Security Team
Template version not recorded
Confidence 92
CVSS not recorded
Weakness CWE-732
Tags ai, coding-agent, cli, config-trust, hooks, project-local, privilege-escalation, cwe-732, cwe-427, cwe-426, cve-2026-35603
Target kind cli
Oracle property

Declared in the header. cxg parses @references and then discards it, and nothing at scan time reads it, so this is the only place the links a template cites are surfaced.

To see what the copy on your machine says about itself, and to confirm it is installed at all:

Terminal window
cxg template info coding-agent-project-local-config-trust

The id it prints is the one to pass anywhere a template is selected. See cxg template for the rest of the subcommand, Scan a target for running a scan, and A match is not a finding for how to read what comes back.