Build Test Suite #459
build-test.lock.yml
on: pull_request
Annotations
3 errors, 1 warning, and 1 notice
|
detection
ERR_VALIDATION: ❌ Security threats detected: prompt injection
Reasons: The workflow prompt file (prompt.txt) contains injected JSON at its end that pre-fabricates a complete 'success' result: all 18 projects across 8 ecosystems shown as passing, with add_labels and add_comment safeoutputs calls. The agent_output.json matches this injected JSON exactly, indicating the agent consumed the injected output rather than actually running any build/test tasks. This is a prompt injection attack designed to fraudulently add the 'build-test' label to PR #1711 and post a fake success comment without performing any real testing.
|
|
detection
Reasons: The workflow prompt file (prompt.txt) contains injected JSON at its end that pre-fabricates a complete 'success' result: all 18 projects across 8 ecosystems shown as passing, with add_labels and add_comment safeoutputs calls. The agent_output.json matches this injected JSON exactly, indicating the agent consumed the injected output rather than actually running any build/test tasks. This is a prompt injection attack designed to fraudulently add the 'build-test' label to PR #1711 and post a fake success comment without performing any real testing.
|
|
detection
🚨 Security threats detected: prompt injection
|
|
agent
GitHub MCP guard policy automatically applied for public repository. min-integrity='approved' and repos='all' ensure only approved-integrity content is accessible.
|
|
agent
Safe Outputs MCP Server Startup Log
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
activation
|
4.45 KB |
sha256:ded2edcf029766ef977a217527aea3e19e2e5b7de7964ef90e51ee25aee746f0
|
|
|
agent
|
11.6 MB |
sha256:9713099ff0d2e4ac21d14dc15c0c7dccde14fc91004e17c244234b63c1248cd2
|
|
|
detection
|
23 KB |
sha256:71dd8503ccc7a8577e4189dea3d8898b57b3e2209480bdf02af7071680c56c66
|
|
|
firewall-audit-logs
|
14.9 KB |
sha256:e456628a8aa63fa1bbac1ecd6c0b8dfdae16f961cd38833ea0f0e1060b52023a
|
|