SG-061: Workflow Untrusted-Input AI Agent

Severity: HIGH

GitHub Actions workflow combining risky trigger, AI-agent action, and untrusted-input interpolation (Comment-and-Control).

Fires when

Remediation

No safe remediation: a file that triggers this rule should be rejected, not patched. Read the flagged lines in the source before deciding.

Research