Collected research
Prompt Injection Inside GitHub Actions: The New Frontier of Supply Chain Attacks
CI workflows paste untrusted issue, pull-request and commit text straight into prompts for AI agents that hold write-scoped tokens and shell tools. A crafted issue body is read as instructions, so the agent uses its own tooling, for example editing the issue, to publish repository tokens, cloud credentials and API keys.
Record
- Researcher
- Rein Daelman
- Published by
- Aikido Security
- Topic
- Injection
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Rein Daelman, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .