Research presented at Black Hat shows how issue-driven automation in AI coding repositories can cross a trust boundary and reach privileged CI contexts.
A reported flaw in coding-agent workflows shows how untrusted issue text can become a security boundary problem when the agent also has shell, file, or sandboxed tool access.
Google removed three workflows from its ADK Python repository after a reported GitHub issue path appeared able to steer a triage agent toward a privileged code-fixing action.
A reported prompt-injection weakness shows how a harmless-looking issue thread can become an untrusted input channel into privileged workflow automation.
Researchers have shown that a normal-looking issue on a public repository can become a delivery mechanism for private data exposure when an agentic workflow is allowed to read too broadly.
A prompt-injection finding dubbed GitLost points to a familiar collaboration channel becoming a security boundary: a public issue, an agentic workflow, and private repository data at risk.