Fix repository config executes a command when the workspace is opened in Claude Code
A hook or task declared in this repository runs without any further action from the developer: a `SessionStart` hook, a task with `runOn: folderOpen`, or a dev container lifecycle command. Anyone who clones the repository and opens it runs that command. That is remote code execution with a social step small enough not to count as one.
high likely Claude Code CWE-829 / ASI ASI05
The vulnerable pattern in Claude Code
This finding comes from the Claude Code fixture in the owlwarden test suite. Anyone who clones this repository and opens it runs `node .claude/setup.mjs`, with their own credentials and their own filesystem, before they have read a line of the code.
The corrected configuration
Remove the `SessionStart` entry from `.claude/settings.json`. If your team needs it, put it in user settings (`~/.claude/settings.json`), which a repository cannot write. Platform teams should set `allowManagedHooksOnly` in managed settings so only hooks the organisation ships can load at all.
// .claude/settings.json
{
"hooks": {
// SessionStart removed - run setup with `pnpm setup` instead
}
}
If you are not using Claude Code
Delete the open-time entry. If the command genuinely has to run, move it to user- or platform-level configuration, which a cloned repository cannot write, and leave the repository with a task the developer starts on purpose.
Check your own repository
npx owlwarden scan
npx owlwarden explain agent-hook-autoexec
Runs on your machine. No account, no telemetry, no network unless you ask. In CI, SARIF uploads to code scanning and the exit code is the gate.
Other Claude Code checks
Rules with a tested Claude Code example.
- agent-config-env-redirect high Repository config redirects the agent's API traffic
- agent-config-loader-script high Executable script inside an agent or editor config directory
- agent-config-secret-reachable high Repository config puts credentials in reach of a repository-controlled command
- agent-hook-untrusted-command high Hook command reaches outside the project
- agent-instructions-directive medium Instruction file tells the agent to bypass its own controls
- agent-instructions-hidden-text high Instruction file contains text a human reader cannot see
- agent-marketplace-untrusted medium Repository config adds a third-party plugin or skill source
- agent-mcp-unpinned-remote medium MCP server declaration resolves code at run time
- agent-permission-wildcard medium Repository config pre-approves a broad tool permission
agent-hook-autoexec for every agent host / All rules / owlwarden