Demystifying and Detecting Agentic Workflow Injection Vulnerabilities in GitHub Actions
Fuente:
arXiv
Saved in:
| Main Authors: | Wang, Shenao, Hou, Xinyi, Liu, Zhao, Zhao, Yanjie, Cheng, Xiao, Zou, Quanchen, Zhang, Xiangzheng, Wang, Haoyu |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
SoK: Understanding Vulnerabilities in the Large Language Model Supply Chain
by: Wang, Shenao, et al.
Published: (2025)
by: Wang, Shenao, et al.
Published: (2025)
Unpacking Security Scanners for GitHub Actions Workflows
by: Fares, Madjda, et al.
Published: (2026)
by: Fares, Madjda, et al.
Published: (2026)
Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions
by: Hou, Xinyi, et al.
Published: (2025)
by: Hou, Xinyi, et al.
Published: (2025)
Demystifying Cookie Sharing Risks in WebView-based Mobile App-in-app Ecosystems
by: Zhang, Miao, et al.
Published: (2025)
by: Zhang, Miao, et al.
Published: (2025)
On the effectiveness of Large Language Models for GitHub Workflows
by: Zhang, Xinyu, et al.
Published: (2024)
by: Zhang, Xinyu, et al.
Published: (2024)
Granite: Granular Runtime Enforcement for GitHub Actions Permissions
by: Moazen, Mojtaba, et al.
Published: (2025)
by: Moazen, Mojtaba, et al.
Published: (2025)
Heimdallr: Characterizing and Detecting LLM-Induced Security Risks in GitHub CI Workflows
by: Ruan, Bonan, et al.
Published: (2026)
by: Ruan, Bonan, et al.
Published: (2026)
"Your AI, My Shell": Demystifying Prompt Injection Attacks on Agentic AI Coding Editors
by: Liu, Yue, et al.
Published: (2025)
by: Liu, Yue, et al.
Published: (2025)
Is GitHub's Copilot as Bad as Humans at Introducing Vulnerabilities in Code?
by: Asare, Owura, et al.
Published: (2022)
by: Asare, Owura, et al.
Published: (2022)
Eradicating the Unseen: Detecting, Exploiting, and Remediating a Path Traversal Vulnerability across GitHub
by: Akhoundali, Jafar, et al.
Published: (2025)
by: Akhoundali, Jafar, et al.
Published: (2025)
Models Are Codes: Towards Measuring Malicious Code Poisoning Attacks on Pre-trained Model Hubs
by: Zhao, Jian, et al.
Published: (2024)
by: Zhao, Jian, et al.
Published: (2024)
Security in the Age of AI Teammates: An Empirical Study of Agentic Pull Requests on GitHub
by: Siddiq, Mohammed Latif, et al.
Published: (2026)
by: Siddiq, Mohammed Latif, et al.
Published: (2026)
Automating the Detection of Code Vulnerabilities by Analyzing GitHub Issues
by: Cipollone, Daniele, et al.
Published: (2025)
by: Cipollone, Daniele, et al.
Published: (2025)
SMCP: Secure Model Context Protocol
by: Hou, Xinyi, et al.
Published: (2026)
by: Hou, Xinyi, et al.
Published: (2026)
Security Vulnerabilities in AI-Generated Code: A Large-Scale Analysis of Public GitHub Repositories
by: Schreiber, Maximilian, et al.
Published: (2025)
by: Schreiber, Maximilian, et al.
Published: (2025)
On the (In)Security of LLM App Stores
by: Hou, Xinyi, et al.
Published: (2024)
by: Hou, Xinyi, et al.
Published: (2024)
Seeing is (Not) Believing: Practical Phishing Attacks Targeting Social Media Sharing Cards
by: Huang, Wangchenlu, et al.
Published: (2024)
by: Huang, Wangchenlu, et al.
Published: (2024)
Can Highlighting Help GitHub Maintainers Track Security Fixes?
by: Liu, Xueqing, et al.
Published: (2024)
by: Liu, Xueqing, et al.
Published: (2024)
LLM-Enabled Open-Source Systems in the Wild: An Empirical Study of Vulnerabilities in GitHub Security Advisories
by: Shifat, Fariha Tanjim, et al.
Published: (2026)
by: Shifat, Fariha Tanjim, et al.
Published: (2026)
Characterizing and Modeling the GitHub Security Advisories Review Pipeline
by: Segal, Claudio, et al.
Published: (2026)
by: Segal, Claudio, et al.
Published: (2026)
Exploring User Privacy Awareness on GitHub: An Empirical Study
by: Alfieri, Costanza, et al.
Published: (2024)
by: Alfieri, Costanza, et al.
Published: (2024)
Towards Robust Detection of Open Source Software Supply Chain Poisoning Attacks in Industry Environments
by: Zheng, Xinyi, et al.
Published: (2024)
by: Zheng, Xinyi, et al.
Published: (2024)
"Elementary, My Dear Watson." Detecting Malicious Skills via Neuro-Symbolic Reasoning across Heterogeneous Artifacts
by: Wang, Shenao, et al.
Published: (2026)
by: Wang, Shenao, et al.
Published: (2026)
Robust Privacy: Inference-Time Privacy through Certified Robustness
by: Jin, Jiankai, et al.
Published: (2026)
by: Jin, Jiankai, et al.
Published: (2026)
Security Weaknesses of Copilot-Generated Code in GitHub Projects: An Empirical Study
by: Fu, Yujia, et al.
Published: (2023)
by: Fu, Yujia, et al.
Published: (2023)
Unveiling A Hidden Risk: Exposing Educational but Malicious Repositories in GitHub
by: Masud, Md Rayhanul, et al.
Published: (2024)
by: Masud, Md Rayhanul, et al.
Published: (2024)
LLM Agents for Automated Web Vulnerability Reproduction: Are We There Yet?
by: Liu, Bin, et al.
Published: (2025)
by: Liu, Bin, et al.
Published: (2025)
On the Prevalence and Usage of Commit Signing on GitHub: A Longitudinal and Cross-Domain Study
by: Sharma, Anupam, et al.
Published: (2025)
by: Sharma, Anupam, et al.
Published: (2025)
Bugdar: AI-Augmented Secure Code Review for GitHub Pull Requests
by: Naulty, John, et al.
Published: (2025)
by: Naulty, John, et al.
Published: (2025)
Evaluating and Enhancing the Vulnerability Reasoning Capabilities of Large Language Models
by: Lu, Li, et al.
Published: (2026)
by: Lu, Li, et al.
Published: (2026)
Unveiling the Landscape of LLM Deployment in the Wild: An Empirical Study
by: Hou, Xinyi, et al.
Published: (2025)
by: Hou, Xinyi, et al.
Published: (2025)
Reasoning-Oriented Programming: Chaining Semantic Gadgets to Jailbreak Large Vision Language Models
by: Zou, Quanchen, et al.
Published: (2026)
by: Zou, Quanchen, et al.
Published: (2026)
IssueGuard: Real-Time Secret Leak Prevention Tool for GitHub Issue Reports
by: Rahman, Md Nafiu, et al.
Published: (2026)
by: Rahman, Md Nafiu, et al.
Published: (2026)
LLM App Squatting and Cloning
by: Xie, Yinglin, et al.
Published: (2024)
by: Xie, Yinglin, et al.
Published: (2024)
Directed Greybox Fuzzing via Large Language Model
by: Xu, Hanxiang, et al.
Published: (2025)
by: Xu, Hanxiang, et al.
Published: (2025)
Six Million (Suspected) Fake Stars in GitHub: A Growing Spiral of Popularity Contests, Spams, and Malware
by: He, Hao, et al.
Published: (2024)
by: He, Hao, et al.
Published: (2024)
Enhancing Security of AI-Based Code Synthesis with GitHub Copilot via Cheap and Efficient Prompt-Engineering
by: Res, Jakub, et al.
Published: (2024)
by: Res, Jakub, et al.
Published: (2024)
AgentVisor: Defending LLM Agents Against Prompt Injection via Semantic Virtualization
by: Ying, Zonghao, et al.
Published: (2026)
by: Ying, Zonghao, et al.
Published: (2026)
CanCal: Towards Real-time and Lightweight Ransomware Detection and Response in Industrial Environments
by: Wang, Shenao, et al.
Published: (2024)
by: Wang, Shenao, et al.
Published: (2024)
How Agentic AI Coding Assistants Become the Attacker's Shell
by: Liu, Yue, et al.
Published: (2026)
by: Liu, Yue, et al.
Published: (2026)
Similar Items
-
SoK: Understanding Vulnerabilities in the Large Language Model Supply Chain
by: Wang, Shenao, et al.
Published: (2025) -
Unpacking Security Scanners for GitHub Actions Workflows
by: Fares, Madjda, et al.
Published: (2026) -
Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions
by: Hou, Xinyi, et al.
Published: (2025) -
Demystifying Cookie Sharing Risks in WebView-based Mobile App-in-app Ecosystems
by: Zhang, Miao, et al.
Published: (2025) -
On the effectiveness of Large Language Models for GitHub Workflows
by: Zhang, Xinyu, et al.
Published: (2024)