The case concerns reported attacks on GitHub Actions workflows using Anthropic’s Claude Code, Google’s Gemini CLI, and OpenAI’s Codex, where untrusted issue content could reach privileged CI capabilities. Supplied reporting describes distinct outcomes—API-key exfiltration, host command execution, and changes to instructions for subsequent agent runs—rather than establishing the same RCE in all three. The snippets do not include Novee’s original report or establish the claimed unauthenticated, vendor-default attack path across all three; separate GMO Flatt research says Claude Code Actions blocks non-write users by default, with an explicitly risky option to bypass that restriction.
Scott already holds the relevant position in Taint Tracking and SiloOS: untrusted text must not authorise privileged actions, and agent containment must be structural; this report supplies another example, not an established challenge to his designs or evidence that his deployments are affected. The radar tracks related attacks, not this exact report, and the supplied grounding does not establish the headline’s unauthenticated vendor-default RCE claim across all three vendors.
ip:concept.taint-trackingip:framework.siloosip:concept.confused-deputy-problemradar:agent-context-privilege-escalationradar:issuetrojanbench-malicious-issue-attacksradar:repository-content-agent-injection
queries asked of Scott's wikis
- coding agent harness trust boundaries untrusted input
- GitHub Actions issue triage agent permissions secrets
- prompt injection tool execution sandbox isolation
- vendor defaults agent security guarantees
- agent instruction persistence repository configuration poisoning
now 0 pts/hpeak 0 pts/hcomments 0/hpeers p14momentum: steady3 platformsage 1610h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion
2026-09-19T13:30:52Z
The new HN attachment supplies only a generic zero-click RCE headline, with no article, technical details, or identifiable research lineage; it cannot support the attachment rationale's claim of independent corroboration. The specific unauthenticated vendor-default GitHub Actions allegation remains contested, with no demonstrated expansion in implementations or affected users.
2026-09-19T13:21:56Z
evidence attached: hn.story.49766285 — Independent security coverage corroborates the open case that default coding-agent action configurations can expose untrusted issue processing to zero-click RCE and credential theft.
2026-09-18T14:30:28Z
The PhantomFix attachment concerns Sentry Seer, not the three vendors’ GitHub Actions defaults, and supplies only an HN headline—not the CERT report asserted in the attachment rationale. It adds a related allegation, not independent corroboration of this case’s unauthenticated issue-to-execution claim.
2026-09-18T14:22:31Z
evidence attached: hn.story.49754342 — Independent CERT reporting materially corroborates that untrusted bug or issue content can induce coding agents to execute attacker-controlled code.
2026-09-18T01:38:33Z
The Plugin4Shell attachment does not independently corroborate the GitHub issue-to-execution allegation: the available discussion describes a different, plugin-installation attack path. The attachment rationale overstates the evidence; the original vendor-default claim remains contested and unverified.
2026-09-18T01:21:38Z
evidence attached: hn.story.49745809 — This is independent corroboration of serious default-execution vulnerabilities across coding-agent integrations, strengthening the open RCE episode.
2026-09-15T13:44:31Z
The discussion adds no independently supported exploit details; the Gemini runtime-setting allegation remains testimony rather than verification. Cool the case: the broad claim of unauthenticated RCE in all three vendors’ defaults remains unproven, especially given the reported Claude Actions permission gate.
2026-09-14T03:26:16Z
grounded: known/low — Scott already holds the relevant position in Taint Tracking and SiloOS: untrusted text must not authorise privileged actions, and agent containment must be stru
2026-09-14T03:23:28Z
origin walked (codex/luna, conf 0.96): anchor reddit.post.1wfr3vz -> echo.blog.6488aed900 by Novee Security (Elad Meged)
2026-09-14T03:21:51Z
case created — The cross-vendor RCE allegation includes a concrete validator failure and merits follow-up, but researcher attribution, affected versions, and remediation remain unestablished.