Find CI agents that eat untrusted GitHub events and hold secrets. Static recon for the clinejection class (untrusted issue -> AI agent step -> npm token -> publish), a harmless canary 'prove' mode, and a local agent-config audit.
security supply-chain sast github-actions ai-agent ci-security prompt-injection agent-security clinejection
-
Updated
Sep 1, 2026 - Python