Wire
Coding agents turn GitHub issues into CI risk
Security researchers found a repeatable trust-boundary flaw across Claude Code, Gemini CLI, and OpenAI Codex: a single unprivileged GitHub issue could reach a CI runner and expose workflow credentials under the vendors’ default configurations. The Novee disclosure says Google rated its Gemini CLI path CVSS 10.0 and that the downstream tool has roughly two million monthly installs; Anthropic patched its path while Google shipped a breaking trust-model change. Teams moving from permission fatigue to auto-execution should audit every agent-triggered workflow as a supply-chain boundary, not assume a human approval prompt will catch the handoff.