A trust-boundary flaw in six code agents shows how a malicious repository can manipulate sandboxed tools, not by breaking the model, but by abusing path handling and approval design.