A GitHub repo with zero malicious code can talk an AI coding agent into opening a reverse shell — a fake setup error, a DNS TXT record, a base64 payload. Here's how the indirection chain works and how runtime interception stops it.