Skip to main content
تشغيل أي مهارة في Manus
بنقرة واحدة

cicd-bot-command-injection

Use when hunting CI/CD bot comment command vulnerabilities where issue_comment or pull_request_review_comment triggers invoke privileged workflows without verifying the commenter's identity or authorization. Trigger on: "bot command injection", "issue_comment trigger", "@github-actions", "slash command CI", "CI bot command", "comment triggered workflow", "unauthenticated bot", "github-actions publish", "comment dispatch", no authorization check on workflow_dispatch from comment, chatops CI/CD, supply chain via PR comment.

النجوم٤
التفرعات١
آخر تحديث١٤ مارس ٢٠٢٦ في ١٣:١٧
SKILL.md
readonly