# git non-intrusive clone

5 messages from 2026-10-07 to 2026-10-07. Participants: Luca Di Carlo, D. Ben Knoble, Nico Williams.
Thread: https://gitlist.dev/t/66481

## Luca Di Carlo, 2026-10-07 08:40

Subject: git non-intrusive clone
Message-ID: <e30c5b13-5ca3-43d1-a87a-d807b71bad7b@app.fastmail.com>
URL: https://gitlist.dev/e/e30c5b13-5ca3-43d1-a87a-d807b71bad7b%40app.fastmail.com

```
Hey everyone,
I am reading more and more blog posts about job interviews that require the people to git clone a malicious repo with commands executed using git hooks. 
I wonder if we could have a 
`git clone --non-intrusive ...` 
That would disable all git settings set within the repo. 
Maybe by adding a `.nogitconfig` file or something, so that the developers remember that because of this file, he cannot push or fetch, or use any `.git/` defined stuff. 

I hope this is the right channel, sorry if it's not. 

Thank you for all your work,
Kind regards
Luca

Cordialement
Luca Di Carlo 


```

## D. Ben Knoble, 2026-10-07 18:54

Subject: Re: git non-intrusive clone
Message-ID: <CALnO6CCTbWLn2rO9ASr+5K07vqkaWCx+H8NsCxaAMgHUYR=z5g@mail.gmail.com>
URL: https://gitlist.dev/e/CALnO6CCTbWLn2rO9ASr%2B5K07vqkaWCx%2BH8NsCxaAMgHUYR%3Dz5g%40mail.gmail.com
In-Reply-To: <e30c5b13-5ca3-43d1-a87a-d807b71bad7b@app.fastmail.com>

```
I may have misunderstood, but…

On Wed, Oct 7, 2026 at 4:40 AM Luca Di Carlo <luca@dicarlo.email> wrote:
>
> Hey everyone,
> I am reading more and more blog posts about job interviews that require the people to git clone a malicious repo with commands executed using git hooks.

I don't think a _clone_ can ship and enable hooks on its own. (I know
of at least one npm package that wants to install Git hooks when you
run "npm i"/"npm ci", though… turn on "ignore-scripts" for that.) That
is, you should be very careful executing anything from a cloned
repository you don't trust, but I don't think a clone can ship
executable hooks in a meaningful way.

What *can* get you is an archive that includes ".git/", since it can
contain hooks that Git will execute (modulo safe.directory, I think,
but that typically doesn't apply in these situations). So: also be
careful extracting arbitrary archives!

Maybe you had other security flaw in mind, or maybe someone else can
tell me how we fix this beyond "tell folks to be careful" (which I
agree doesn't scale well).

-- 
D. Ben Knoble


```

## Luca Di Carlo, 2026-10-07 19:19

Subject: Re: git non-intrusive clone
Message-ID: <d6dc70f6-f155-4a5a-b647-ac24b2b1ed37@app.fastmail.com>
URL: https://gitlist.dev/e/d6dc70f6-f155-4a5a-b647-ac24b2b1ed37%40app.fastmail.com
In-Reply-To: <CALnO6CCTbWLn2rO9ASr+5K07vqkaWCx+H8NsCxaAMgHUYR=z5g@mail.gmail.com>

```
Hey,
You are right, I've re-read the article that I had in mind, he downloads it as zip before, not as clone.
`.git` is not cloned. 
Sorry for that. 
Thanks

On Wed, Oct 7, 2026, at 20:54, D. Ben Knoble wrote:
> I may have misunderstood, but…
> 
> On Wed, Oct 7, 2026 at 4:40 AM Luca Di Carlo wrote:
> >
> > Hey everyone,
> > I am reading more and more blog posts about job interviews that require the people to git clone a malicious repo with commands executed using git hooks.
> 
> I don't think a _clone_ can ship and enable hooks on its own. (I know
> of at least one npm package that wants to install Git hooks when you
> run "npm i"/"npm ci", though… turn on "ignore-scripts" for that.) That
> is, you should be very careful executing anything from a cloned
> repository you don't trust, but I don't think a clone can ship
> executable hooks in a meaningful way.
> 
> What *can* get you is an archive that includes ".git/", since it can
> contain hooks that Git will execute (modulo safe.directory, I think,
> but that typically doesn't apply in these situations). So: also be
> careful extracting arbitrary archives!
> 
> Maybe you had other security flaw in mind, or maybe someone else can
> tell me how we fix this beyond "tell folks to be careful" (which I
> agree doesn't scale well).
> 
> -- 
> D. Ben Knoble
> 

Luca


```

## D. Ben Knoble, 2026-10-07 19:50

Subject: Re: git non-intrusive clone
Message-ID: <CALnO6CA5tY5Ebw5JyA8c-e00PqLcXMAijA5VF6DrPJNDCX=raA@mail.gmail.com>
URL: https://gitlist.dev/e/CALnO6CA5tY5Ebw5JyA8c-e00PqLcXMAijA5VF6DrPJNDCX%3DraA%40mail.gmail.com
In-Reply-To: <d6dc70f6-f155-4a5a-b647-ac24b2b1ed37@app.fastmail.com>

```
On Wed, Oct 7, 2026 at 3:20 PM Luca Di Carlo <luca@dicarlo.email> wrote:
>
> Hey,
> You are right, I've re-read the article that I had in mind, he downloads it as zip before, not as clone.
> `.git` is not cloned.
> Sorry for that.
> Thanks

[we bottom-post here ;)]

No worries! I think in the past Git has said "that's not really part
of our security model", but I don't have any authoritative references.

Still, definitely worth having the conversation, and I'm glad we
figured it out together. I'm still somewhat interested in what we can
do besides "try to tell folks not to blindly trust downloaded files"…
but that's never going to stop being bad advice :)

-- 
D. Ben Knoble


```

## Nico Williams, 2026-10-07 20:26

Subject: Re: git non-intrusive clone
Message-ID: <asaq9MaTvtuFyrpm@ubby>
URL: https://gitlist.dev/e/asaq9MaTvtuFyrpm%40ubby
In-Reply-To: <CALnO6CA5tY5Ebw5JyA8c-e00PqLcXMAijA5VF6DrPJNDCX=raA@mail.gmail.com>

```
On Wed, Oct 07, 2026 at 03:50:43PM -0400, D. Ben Knoble wrote:
> Still, definitely worth having the conversation, and I'm glad we
> figured it out together. I'm still somewhat interested in what we can
> do besides "try to tell folks not to blindly trust downloaded files"…
> but that's never going to stop being bad advice :)

There have been horror stories about phishing via fake interviews.
There is no easy way to ascertain the trustworthiness of such code.
Just don't run that code.  Use a hosted VM service for this or insist
that they use a code pad type web application -- that they don't use
those is a red flag.

Nico
-- 


```
