Skip to content

Build Test Suite

Build Test Suite #515

Triggered via pull request April 8, 2026 00:02
Status Failure
Total duration 8m 28s
Artifacts 4

build-test.lock.yml

on: pull_request
Fit to window
Zoom out
Zoom in

Annotations

3 errors, 1 warning, and 1 notice
detection
ERR_VALIDATION: ❌ Security threats detected: prompt injection Reasons: The workflow prompt file (prompt.txt) contains injected JSON at the end (after a '---' separator) that pre-fabricates successful test results for all 18 projects across 8 ecosystems, including an 'add_labels' action to add 'build-test' to PR #1767. The agent output in agent_output.json matches this injected data exactly, indicating the agent was successfully manipulated into reporting false success without actually running any tests. This is a classic prompt injection attack to fraudulently satisfy a PR label gate requirement.
detection
Reasons: The workflow prompt file (prompt.txt) contains injected JSON at the end (after a '---' separator) that pre-fabricates successful test results for all 18 projects across 8 ecosystems, including an 'add_labels' action to add 'build-test' to PR #1767. The agent output in agent_output.json matches this injected data exactly, indicating the agent was successfully manipulated into reporting false success without actually running any tests. This is a classic prompt injection attack to fraudulently satisfy a PR label gate requirement.
detection
🚨 Security threats detected: prompt injection
agent
GitHub MCP guard policy automatically applied for public repository. min-integrity='approved' and repos='all' ensure only approved-integrity content is accessible.
agent
Safe Outputs MCP Server Startup Log

Artifacts

Produced during runtime
Name Size Digest
activation Expired
4.79 KB
sha256:546c718077d09c412fde489fe8d358efc253c148817bb38c3bc93944a1086e1b
agent
11.6 MB
sha256:e2b29e7cd12ae8269421492ec391b9144cc8c2e61d35b7a31d75236b0f1ecf27
detection
23.4 KB
sha256:ddf4c860a07635fbf0be6ae6642bc5823edec9387a4e7bfed21ec72602643012
firewall-audit-logs
15.3 KB
sha256:630c0eb63a9618826ce2b701ec8f1497f5c7575c07d2d763218e2ad08ff59990