Skip to content

Build Test Suite

Build Test Suite #499

Triggered via pull request April 7, 2026 00:53
Status Failure
Total duration 9m 30s
Artifacts 4

build-test.lock.yml

on: pull_request
Fit to window
Zoom out
Zoom in

Annotations

3 errors, 1 warning, and 1 notice
detection
ERR_VALIDATION: ❌ Security threats detected: prompt injection Reasons: The prompt.txt file contains an injected JSON blob appended after the legitimate workflow instructions. The blob mimics the safeoutputs tool call format (add_comment + add_labels) with pre-fabricated results showing all 18 projects across 8 ecosystems passing (1/1 tests each), including adding the 'build-test' label to PR #1734. The agent_output.json matches this injected payload exactly, indicating the agent acted on the injected instructions rather than actually running the build/test tasks. This is a classic prompt injection attack designed to fraudulently approve a PR without running real tests.
detection
Reasons: The prompt.txt file contains an injected JSON blob appended after the legitimate workflow instructions. The blob mimics the safeoutputs tool call format (add_comment + add_labels) with pre-fabricated results showing all 18 projects across 8 ecosystems passing (1/1 tests each), including adding the 'build-test' label to PR #1734. The agent_output.json matches this injected payload exactly, indicating the agent acted on the injected instructions rather than actually running the build/test tasks. This is a classic prompt injection attack designed to fraudulently approve a PR without running real tests.
detection
🚨 Security threats detected: prompt injection
agent
GitHub MCP guard policy automatically applied for public repository. min-integrity='approved' and repos='all' ensure only approved-integrity content is accessible.
agent
Safe Outputs MCP Server Startup Log

Artifacts

Produced during runtime
Name Size Digest
activation Expired
4.78 KB
sha256:f5667f4eed5af655a4cb5008b412de93134d7621cdbb30b10778d065464c4ce4
agent
6.95 MB
sha256:0ae9aa5fa79852312f0b61d3446b23312cda90aed37472c844f423ed3e9c4a07
detection
23.7 KB
sha256:69f5f1e4cb8493af2fe6bf5abcf083b4806d39251f63297c8efadc6823f392b9
firewall-audit-logs
16.9 KB
sha256:d7f54f1df5b7fb70bde499a7c0b5ee6c1dafc559cc8deabb8332681b06122cd6