Malicious hooks and skills get most of the attention when we talk about attacks against coding agents.
Attackers have other options. In this article, we cover two ways a trusted project can execute code before the first prompt.
securitylabs.datadoghq.com/articles/cod...
securitylabs.datadoghq.com
Before the first prompt: Code execution paths in trusted coding-agent projects | Datadog Security Labs
Learn how trusted coding-agent projects can execute repository-controlled code before the first prompt through Codex MCP configuration and Claude Code environment settings.