The (In)security Landscape of AI-Powered GitHub Actions (Part 2/2)
wiz.io | blog | #ai-security | #supply-chain | #vulnerability-research | #github-actions | #prompt-injection | #ci-cd
Summary
Part 2 of Wiz's GitHub Actions research: AI actions from OpenAI, Anthropic, and Google have config bypasses outsiders can trigger; dynamic credential files create a novel exfiltration vector.
- Published
- Collected
Skip to content