Gemini CLI and Claude Code flaws let untrusted GitHub input reach CI workflows, including host command execution and API key exposure.

Pillar Security found a prompt injection attack that lets a public AI agent compromise a privileged one in Google's gemini-cli, leaking GitHub

Gemini CLI and Claude Code flaws let untrusted GitHub input reach CI workflows, including host command execution and API key exposure.