Web Hack List

Preliminary research

LGTM: Bypassing an LLM Build Gate When Prompt Injection Fails

AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

OpenSearch guards pull_request_target CI with a step that curls the PR diff into a Claude prompt, failing the build at medium severity or above. The gate sees about three lines of context, cannot open implementation files kept in another repository, and never sees the author. Base64-wrapped payloads were blocked in 24 of 25 runs, and the diff arrives as user text with no system-prompt boundary, so both evasions are re-rollable coin flips.

Record

Researcher
Aviv Donenfeld
Published by
media.defcon.org
Format
Whitepaper
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Aviv Donenfeld, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .