AI Agents in GitHub Actions: A Critical Prompt-Injection RCE
中文摘要
GitHub Actions AI 代理存在严重提示注入 RCE 漏洞,可通过 fork 触发。扫描显示 85,214 个工作流面临风险,安全门已洞开。
English Summary
AI agents in GitHub Actions are vulnerable to prompt-injection RCE via fork-triggers. A scan found widespread risk in 85,214 workflows, indicating an open door for exploitation.
原文节选
Fork-triggerable AI agents are running wild in CI, and a scan of 85,214 real workflows shows the door is already open Continue reading on Medium »