INITIALIZING…
SYSTEMS
00
00
Tushaar Naagar
Back to writing

Security

Your Coding Agent in CI Is a New Attack Surface

Aug 20, 20262 min read

Black Hat 2026 showed that a public GitHub issue can reach CI secrets if an agent is wired into the pipeline. Isolation beats a smarter model.

What actually shipped at Black Hat

In early August, researchers showed that Claude Code, Gemini CLI, and Codex — running in each vendor's own public repos — could be steered from an unprivileged GitHub issue. No write access. No prior relationship with the maintainers. The agent was already in CI, with tokens, because that's the product pitch: file a ticket, let the bot patch it. Two of the findings became CVEs. OpenAI treated theirs as documented sandbox behavior and still split their own two-pass workflow into isolated jobs within days. If the vendors' pipelines were in scope, yours is too.

The pattern, not the CVE list

The model is not the bug. The bug is treating untrusted issue text as instructions, then giving that process a GitHub token, an API key, or a writable checkout. Agents fetch URLs, write files the next job will trust (AGENTS.md is the obvious one), and inherit whatever permissions the workflow was given 'so it can open a PR.' Prompt injection in CI is just confused deputy with better copy. Patching a version helps. Changing the trust boundary is the actual fix.

What I'd change in a pipeline this week

Don't run a coding agent on issue or PR bodies with write tokens. Split 'read the ticket' and 'apply a patch' into separate jobs with separate checkouts — the second job should never see the raw issue text. Pin agent CLIs; the Gemini and Claude Code advisories were version-specific. Treat AGENTS.md and similar instruction files as deploy artifacts, not something a previous agent pass is allowed to rewrite. If you need an agent in CI at all, give it a read-only token and a human merge. That's slower. It's also how you keep a stranger's issue from becoming a credential dump.

Takeaway

Coding agents in CI are another principal in your threat model. Review their workflows the way you'd review a GitHub App: least privilege, no trust in user-controlled text, and no standing secrets on the runner. The July model wave made agents useful. August made them a security review item.