Manifold Security
Sources: Manifold Security (homepage) · GitSpawn disclosure, 2026-09-01 · CVE-2026-71963
Identity and role
Security vendor selling runtime observation of AI agent behaviour. It has also published original vulnerability research against coding agents, credited on the GitSpawn disclosure to Francisco Rosales, an offensive security engineer at the company.
Relevance to this wiki
GitSpawn is eight findings across seven CLI coding agents, published on 2026-09-01 under one mechanism: a context-gathering git subprocess that executes a program the repository’s own configuration names. It covers Claude Code, Goose, Qwen Code, Grok Build, Hermes, OpenAI Codex and Cursor, and it produced two CVE identifiers, one of them assigned by VulnCheck after the vendor left the report untriaged. For a wider agent population under a different flaw class, see the GuardFall audit, which surveyed eleven open-source coding agents in June 2026.
The company reports that it withheld the configuration key behind one unpatched finding and published no proof-of-concept repository, giving a sink, a trigger and a screen recording per finding instead.
Positions
Manifold’s stated product thesis is that endpoint detection sees familiar developer tooling behaving familiarly and a gateway sees authenticated traffic it already permits, so neither instrument carries a view of what an agent decided to do. That argument is a vendor pitch as well as a research finding, and it belongs to the instrumentation camp catalogued at Inline Gateway vs Runtime Instrumentation. The GitSpawn class is the sharper form of the same claim, because the executing subprocess is the agent’s own rather than one the model requested.
The company also generalizes the finding past git: skills, MCP servers and plugins arrive as files, carry their own configuration and are trusted on arrival for the reason a copied repository is.
No independent assessment
Nothing here describes Manifold’s product beyond its own marketing copy. The company is absent from the September 2026 runtime-protection canvass, which graded twenty-one products against the D4 L4 capability set, so its coverage of those capabilities is ungraded. Funding, headcount and customer base are unrecorded.
Outputs
| Date | Output | Form |
|---|---|---|
| 2026-09-01 | GitSpawn | Eight coding-agent code-execution findings; two CVEs |