Skip to main content
Execute qualquer Skill no Manus
com um clique

cicd-bot-command-injection

Use when hunting CI/CD bot comment command vulnerabilities where issue_comment or pull_request_review_comment triggers invoke privileged workflows without verifying the commenter's identity or authorization. Trigger on: "bot command injection", "issue_comment trigger", "@github-actions", "slash command CI", "CI bot command", "comment triggered workflow", "unauthenticated bot", "github-actions publish", "comment dispatch", no authorization check on workflow_dispatch from comment, chatops CI/CD, supply chain via PR comment.

Estrelas4
Forks1
Atualizado14 de março de 2026 às 13:17
SKILL.md
readonly