Attackers can inject indirect prompts in normal-looking repositories to trick Claude Code into spawning a reverse shell.
This is useful if you are working with a monorepo that contains sub-projects, modules, libraries or deployments with different Python dependencies. Or perhaps you want to automatically activate a ...