A proof-of-concept around agentic coding tools shows how repository content, setup logic, and hidden instructions can be chained into remote shell execution.