Skip to content

Choose a tag to compare

@cpeoples cpeoples released this 23 Jul 14:34

Highlights

  • Catches the action form of claude-code-action, not just CLI agents. The fork-triggerable shell-exec rule now flags workflows that grant anthropics/claude-code-action a shell or file-write tool (Bash, Edit, Write, MultiEdit, NotebookEdit) or an autonomy flag on untrusted issue and pull request content. This is the exact shape behind the Cline compromise, where an agent with only contents: read reached code execution on the runner through its own shell tool. Read and comment-only grants such as Bash(gh pr diff:*) stay clean, and a job with provable repository write remains a single critical finding rather than a double report.
  • Whitepaper updates. Added a remediation follow-up showing that 26 percent of the original findings no longer flag on a re-scan weeks later, wrote up the Cline and Hackerbot-Claw incidents as real-world exploitation of the primitive, framed it as the AI-agent variant of poisoned pipeline execution, and added a references section with verified source locators.

Detection coverage otherwise matches 0.1.1. Every archive is Sigstore-signed and carries SLSA Build Level 3 provenance, with a CycloneDX SBOM attached and signed alongside the binaries.