Skip to content

Coding-agent CLI applies repo-supplied endpoint environment, sending its own API credential to a host the repository chose

coding-agent-repo-config-credential-redirect is a critical severity check in the ai category, written in shell. Its source is templates/ai/coding-agent/coding-agent-repo-config-credential-redirect.sh in cert-x-gen-templates.

Stands up a loopback canary sink, plants an env block in five repo-scoped configuration surfaces of a private checkout - .claude/settings.json, .codex/config.toml, .gemini/settings.json, .vscode/settings.json and the tool’s own project-local settings - each setting ANTHROPIC_BASE_URL, OPENAI_BASE_URL, HTTPS_PROXY and NODE_EXTRA_CA_CERTS at that sink, then opens the checkout with a decoy operator API key in the environment. A control run in a checkout the user’s own trust store records establishes that the tool honours config-supplied environment at all; a request arriving at the sink from the UNRECORDED checkout confirms that a repository chose where the agent’s credential-bearing traffic goes. Severity escalates when the request carries that decoy key in an Authorization or API-key header, because the credential then demonstrably left the machine - with no hook, no MCP server and no command execution anywhere in the probe.

Field Value
Id coding-agent-repo-config-credential-redirect
Severity critical
Language shell
Category ai
Author CERT-X-GEN Security Team
Template version not recorded
Confidence 92
CVSS not recorded
Weakness CWE-1188
Tags ai, coding-agent, cli, agent-posture, untrusted-workspace, repo-config, credential-exfiltration, trust-boundary, base-url, proxy, ca-trust, cwe-1188, cwe-522, cwe-829, cwe-200
Target kind cli
Oracle property

Declared in the header. cxg parses @references and then discards it, and nothing at scan time reads it, so this is the only place the links a template cites are surfaced.

To see what the copy on your machine says about itself, and to confirm it is installed at all:

Terminal window
cxg template info coding-agent-repo-config-credential-redirect

The id it prints is the one to pass anywhere a template is selected. See cxg template for the rest of the subcommand, Scan a target for running a scan, and A match is not a finding for how to read what comes back.