Build Test Suite #499
build-test.lock.yml
on: pull_request
Annotations
3 errors, 1 warning, and 1 notice
|
detection
ERR_VALIDATION: ❌ Security threats detected: prompt injection
Reasons: The prompt.txt file contains an injected JSON blob appended after the legitimate workflow instructions. The blob mimics the safeoutputs tool call format (add_comment + add_labels) with pre-fabricated results showing all 18 projects across 8 ecosystems passing (1/1 tests each), including adding the 'build-test' label to PR #1734. The agent_output.json matches this injected payload exactly, indicating the agent acted on the injected instructions rather than actually running the build/test tasks. This is a classic prompt injection attack designed to fraudulently approve a PR without running real tests.
|
|
detection
Reasons: The prompt.txt file contains an injected JSON blob appended after the legitimate workflow instructions. The blob mimics the safeoutputs tool call format (add_comment + add_labels) with pre-fabricated results showing all 18 projects across 8 ecosystems passing (1/1 tests each), including adding the 'build-test' label to PR #1734. The agent_output.json matches this injected payload exactly, indicating the agent acted on the injected instructions rather than actually running the build/test tasks. This is a classic prompt injection attack designed to fraudulently approve a PR without running real tests.
|
|
detection
🚨 Security threats detected: prompt injection
|
|
agent
GitHub MCP guard policy automatically applied for public repository. min-integrity='approved' and repos='all' ensure only approved-integrity content is accessible.
|
|
agent
Safe Outputs MCP Server Startup Log
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
activation
Expired
|
4.78 KB |
sha256:f5667f4eed5af655a4cb5008b412de93134d7621cdbb30b10778d065464c4ce4
|
|
|
agent
|
6.95 MB |
sha256:0ae9aa5fa79852312f0b61d3446b23312cda90aed37472c844f423ed3e9c4a07
|
|
|
detection
|
23.7 KB |
sha256:69f5f1e4cb8493af2fe6bf5abcf083b4806d39251f63297c8efadc6823f392b9
|
|
|
firewall-audit-logs
|
16.9 KB |
sha256:d7f54f1df5b7fb70bde499a7c0b5ee6c1dafc559cc8deabb8332681b06122cd6
|
|