
The malware stopped saying please
A repo config that runs code on open is twenty years old — tasks.json, npm postinstall, git hooks. We built the countermeasures too: Workspace Trust, git not shipping hooks on clone, direnv re-blocking on any change. The AI editors regressed on all of it, then added the new part: the config now writes itself from untrusted input, executes before any classifier or prompt gets a vote, and lands with your account’s access to everything you’ve authenticated. Closes with an operator’s appendix: how to lock it down, and where the file hides. Part three of a series, on the device.


