The flaws show how agentic workflows can turn trusted repository signals into privilege-escalation paths that conventional identity and CI/CD controls may not reveal.

Poisoned pull requests contain prompt injection that allows one to control another

The flaws show how agentic workflows can turn trusted repository signals into privilege-escalation paths that conventional identity and CI/CD controls may not reveal.