What a cloned repository can do before you trust it
In a folder you have not trusted, a project's own settings, hooks, and MCP servers wait for your decision. Warden's pre-release verification tested that boundary from the attacker's side.
A repository carries more than code. Settings files, hooks, MCP server definitions, and agent definitions travel with a clone, and a coding agent that honors them is honoring whoever wrote them. Warden’s pre-release verification went at that boundary from the attacker’s side and asked a narrow question: what can a freshly cloned repository make Warden do before you have said you trust its folder? Each path it found is now closed.
Untrusted means it can only tighten
In a folder you have not trusted, a project’s own configuration can make Warden more careful, never less. Its deny and ask rules apply. Its allow rules, extra directories, and any looser permission mode are set aside. None of its hooks run, at any point in the session. Its environment settings, provider endpoints, and the MCP servers named in its settings files are not applied. Trusting the folder is what turns them on.
Approvals a repository cannot ship
Approvals for a project’s MCP servers are stored outside the project, so a repository cannot arrive with its own servers already approved. Each approval is tied to the exact command it approved. If the project later points the same server name at a different program, Warden asks again. Companion tools such as Curator are trusted without a prompt only when their settings are their own and their data lives outside the project, so a repository cannot pass its own files off as remembered context.
Some things hold even after trust
Even in a trusted folder with file edits set to auto-accept, a write that changes what runs next still stops for a decision: anything in the repository’s git folder, in its agent configuration folders, or in its MCP server configuration. The prompt names the protected path, so the stop reads as a reason rather than noise. And an agent defined inside a project can restrict itself to planning, but it cannot grant itself a looser permission mode, trusted folder or not.
The aim is a rule an operator can hold in their head: a cloned repository’s own configuration does not get to loosen anything until you decide it should.
Warden is a working proprietary development build. Supported permission modes and trust behavior will be stated with its public release.
Was this useful?