AgentPod is building a private, secure device for your AI agent.The AgentPod device is coming.Coming soonBe first
We checked this and rejected itsecurity

Datadog warns trusted Claude Code and Codex projects can run code before your first prompt: why it is not safe to use

Datadog says trusting a Claude Code or Codex project can let project-controlled code run before you even send a first prompt.

What happened

Datadog Security Labs said on August 3, 2026 that simply trusting a repository, or project folder, can let some coding agents run project-controlled code before you send your first prompt. In plain terms, a repository is the project files someone shares with you.

The report looked at Claude Code and Codex. It says both products support hooks, which are built-in actions that run at set times. Datadog also found other paths that could run automatically without a model reply and without asking you to approve a shell command, which is a text command that tells your computer to do something.

In Datadog's tests, Codex could start an attacker-controlled process through project-scoped MCP settings. MCP is a way for tools and agents to connect to outside services. The report also says a Claude Code project could change the PATH, which is the list of places your computer checks for programs, so Claude's own Git checks ran a repository wrapper instead.

What it means for you

If you open or trust an unfamiliar coding project, that step alone may carry risk, even before you ask the agent to do anything. A project can look normal and still trigger local actions.

What to do instead

Be careful with projects from people or sources you do not know well. Do not trust a repository until you have checked where it came from. If possible, open unfamiliar projects in a separate account, workspace, or test machine. Review project settings before enabling trust. If your agent offers approval or trust options, use the most limited setting first.

If you use shared skills or starter projects, prefer curated sources. AgentPod lists only reviewed, tested skills, which can reduce risk, though no list removes the need for care.

Sources:

  • https://securitylabs.datadoghq.com/articles/coding-agent-project-trust-code-execution-before-first-prompt/

Source: https://securitylabs.datadoghq.com/articles/coding-agent-project-trust-code-execution-before-first-prompt/

We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.

Copied to clipboard. Paste it into your AI (ChatGPT, Claude, or your agent) to add the skill.