“Git reads it from the repository’s own .git/config. Any operation that refreshes the index, including git status and git diff, executes that command.”

Clone a repo, run a routine git status, and a coding agent executes whatever the attacker stuffed into core.fsmonitor. No prompt, no warning, full user privileges. These agents trust the repo they’re sitting in. That trust is now a supply chain hole and nobody flagged it before shipping.