Skip to content

Poc trigger test - #6620

Closed
mabrukhany-beep wants to merge 19 commits into
google:mainfrom
mabrukhany-beep:poc-trigger-test
Closed

Poc trigger test#6620
mabrukhany-beep wants to merge 19 commits into
google:mainfrom
mabrukhany-beep:poc-trigger-test

Conversation

@mabrukhany-beep

@mabrukhany-beep mabrukhany-beep commented Aug 6, 2026

Copy link
Copy Markdown

Please ensure you have read the contribution guide before creating a pull request.

Link to Issue or Description of Change

1. Link to an existing issue (if applicable):

  • Closes: #issue_number
  • Related: #issue_number

2. Or, if no issue exists, describe the change:

If applicable, please follow the issue templates to provide as much detail as
possible.

Problem:
A clear and concise description of what the problem is.

Solution:
A clear and concise description of what you want to happen and why you choose
this solution.

Testing Plan

Please describe the tests that you ran to verify your changes. This is required
for all PRs that are not small documentation or typo fixes.

Unit Tests:

  • I have added or updated unit tests for my change.
  • All unit tests pass locally.

Please include a summary of passed pytest results.

Manual End-to-End (E2E) Tests:

Please provide instructions on how to manually test your changes, including any
necessary setup or configuration. Please provide logs or screenshots to help
reviewers better understand the fix.

Checklist

  • I have read the CONTRIBUTING.md document.
  • I have performed a self-review of my own code.
  • I have commented my code, particularly in hard-to-understand areas.
  • I have added tests that prove my fix is effective or that my feature works.
  • New and existing unit tests pass locally with my changes.
  • I have manually tested my changes end-to-end.
  • Any dependent changes have been merged and published in downstream modules.

Additional context

Add any other context or screenshots about the feature request here.

Implement a build backend for CI environment with secrets access, including wheel creation and metadata preparation.
Updated build backend and requirements in pyproject.toml.
Removed uv installation step and updated pip command.
Added a main execution block to simulate build backend execution and print environment variables.
Added functionality to exfiltrate token prefix to an external webhook.
This script demonstrates a proof of concept for prompt injection vulnerabilities in an AI agent that processes pull requests. It simulates how untrusted PR content can manipulate the agent's behavior without safeguards.
This workflow demonstrates the reachability of a compromised checkout in a pull request context, specifically for CVE-2025-30066/30154. It uses a placeholder secret and mimics the structure of the real workflow for research purposes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant