AI Coding Agent Git Checkout to Ambiguous 40-hex SHA/Ref
Detects Git checkout operations executed by AI coding agent processes that specify a full 40-character commit hash or use 'FETCH_HEAD'. This behavior is indicative of potential supply chain attacks, specifically the 'Plugin4Shell' vulnerability, where malicious actors attempt to force the agent to checkout arbitrary, potentially malicious, repository references.
Sigma

