Skip to content

Build Test Suite

Build Test Suite #461

Triggered via pull request April 6, 2026 17:39
Status Failure
Total duration 10m 13s
Artifacts 4

build-test.lock.yml

on: pull_request
Fit to window
Zoom out
Zoom in

Annotations

3 errors, 1 warning, and 1 notice
detection
ERR_VALIDATION: ❌ Security threats detected: prompt injection Reasons: The workflow prompt file contains injected JSON at the end (after the legitimate workflow instructions) that pre-fabricates safe-output tool calls claiming all 18 projects across 8 ecosystems passed with '8/8 ecosystems passed — PASS'. This JSON bypasses actual test execution by directly providing fabricated success results to the agent, causing it to add the 'build-test' label to PR #1714 and post a false all-passing summary without running any real builds or tests. This is a classic prompt injection attack where malicious content appended to a legitimate workflow prompt manipulates the agent into reporting false outcomes.
detection
Reasons: The workflow prompt file contains injected JSON at the end (after the legitimate workflow instructions) that pre-fabricates safe-output tool calls claiming all 18 projects across 8 ecosystems passed with '8/8 ecosystems passed — PASS'. This JSON bypasses actual test execution by directly providing fabricated success results to the agent, causing it to add the 'build-test' label to PR #1714 and post a false all-passing summary without running any real builds or tests. This is a classic prompt injection attack where malicious content appended to a legitimate workflow prompt manipulates the agent into reporting false outcomes.
detection
🚨 Security threats detected: prompt injection
agent
GitHub MCP guard policy automatically applied for public repository. min-integrity='approved' and repos='all' ensure only approved-integrity content is accessible.
agent
Safe Outputs MCP Server Startup Log

Artifacts

Produced during runtime
Name Size Digest
activation
4.46 KB
sha256:9c44a5c5d22fcf0a2009340f671f4e8d489feae6317439a57e46bb745bff0559
agent
11.6 MB
sha256:e59b190b5026dc7fbf1fbd37e0ecf7783447775824c485ff55d7a1c8f465342e
detection
23.2 KB
sha256:6e74770b92359b2b19187730df16c18e8bc4563884de070a915f60264aac10c3
firewall-audit-logs
15.5 KB
sha256:0418c53fa455afdede7c3089edeb5ef3c82520d4f72cf3bbe35cac2c22b707d5