Highlights
- Catches the action form of
claude-code-action, not just CLI agents. The fork-triggerable shell-exec rule now flags workflows that grantanthropics/claude-code-actiona shell or file-write tool (Bash,Edit,Write,MultiEdit,NotebookEdit) or an autonomy flag on untrusted issue and pull request content. This is the exact shape behind the Cline compromise, where an agent with onlycontents: readreached code execution on the runner through its own shell tool. Read and comment-only grants such asBash(gh pr diff:*)stay clean, and a job with provable repository write remains a single critical finding rather than a double report. - Whitepaper updates. Added a remediation follow-up showing that 26 percent of the original findings no longer flag on a re-scan weeks later, wrote up the Cline and Hackerbot-Claw incidents as real-world exploitation of the primitive, framed it as the AI-agent variant of poisoned pipeline execution, and added a references section with verified source locators.
Detection coverage otherwise matches 0.1.1. Every archive is Sigstore-signed and carries SLSA Build Level 3 provenance, with a CycloneDX SBOM attached and signed alongside the binaries.