Trusting a repository in a coding agent can give that project a local execution path before you ever type a prompt. The missed assumption is that only approved chat commands matter; Datadog shows project-controlled config and environment settings can trigger code as part of opening the workspace, with no model response or shell approval.
Datadog found this in Codex MCP and Claude Code, and the same startup surface extends to tools like Visual Studio Code. The practical shift is that repo trust now reaches beyond obvious hooks into startup behavior that can expose host credentials before the first interaction.