Build Test Suite #515
build-test.lock.yml
on: pull_request
Annotations
3 errors, 1 warning, and 1 notice
|
detection
ERR_VALIDATION: ❌ Security threats detected: prompt injection
Reasons: The workflow prompt file (prompt.txt) contains injected JSON at the end (after a '---' separator) that pre-fabricates successful test results for all 18 projects across 8 ecosystems, including an 'add_labels' action to add 'build-test' to PR #1767. The agent output in agent_output.json matches this injected data exactly, indicating the agent was successfully manipulated into reporting false success without actually running any tests. This is a classic prompt injection attack to fraudulently satisfy a PR label gate requirement.
|
|
detection
Reasons: The workflow prompt file (prompt.txt) contains injected JSON at the end (after a '---' separator) that pre-fabricates successful test results for all 18 projects across 8 ecosystems, including an 'add_labels' action to add 'build-test' to PR #1767. The agent output in agent_output.json matches this injected data exactly, indicating the agent was successfully manipulated into reporting false success without actually running any tests. This is a classic prompt injection attack to fraudulently satisfy a PR label gate requirement.
|
|
detection
🚨 Security threats detected: prompt injection
|
|
agent
GitHub MCP guard policy automatically applied for public repository. min-integrity='approved' and repos='all' ensure only approved-integrity content is accessible.
|
|
agent
Safe Outputs MCP Server Startup Log
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
activation
Expired
|
4.79 KB |
sha256:546c718077d09c412fde489fe8d358efc253c148817bb38c3bc93944a1086e1b
|
|
|
agent
|
11.6 MB |
sha256:e2b29e7cd12ae8269421492ec391b9144cc8c2e61d35b7a31d75236b0f1ecf27
|
|
|
detection
|
23.4 KB |
sha256:ddf4c860a07635fbf0be6ae6642bc5823edec9387a4e7bfed21ec72602643012
|
|
|
firewall-audit-logs
|
15.3 KB |
sha256:630c0eb63a9618826ce2b701ec8f1497f5c7575c07d2d763218e2ad08ff59990
|
|