Перейти к содержимому
Оригинал
Permission Protocol · AI Agent Incident Tracker·· 17.08.2026Оценка ИИ74

Wiz 红队智能体利用 Snowflake 工作流漏洞,该变更由 GitHub Copilot 共同署名并评估为无风险

Оригинальный заголовок: Wiz Red Agent Exploits Snowflake Workflow Flaw in a Change Co-Authored and Cleared by GitHub Copilot

Заголовок и краткое изложение на выбранном языке ожидают перевода.

Краткий обзор ИИ

Wiz 红队智能体利用 Snowflake 开源仓库 GitHub Actions 工作流中的命令注入漏洞,从 CI/CD 环境窃取 Jira API 凭证,这些凭证可读取 Snowflake 工程、安全合规和漏洞赏金数据库。

Полный текст

Полный текст на выбранном языке ожидает перевода. Пока показан оригинал.

Back to incident tracker

2026-08-17

HighPrimary

Wiz Red Agent Exploits Snowflake Workflow Flaw in a Change Co-Authored and Cleared by GitHub Copilot

Analysis of the Snowflake workflow flaw exploited by Wiz Red Agent after GitHub Copilot was recorded as a co-author and assessed the merged change as all-clear.

GitHub Copilot AutofixTool execution / MCPAI-assisted review failure followed by autonomous exploitationGitHub CI/CD / Snowflake open-source repository

What happened

A vulnerable workflow change is merged after Copilot co-authorship and an all-clear assessment; Wiz Red Agent later exploits command injection to expose Jira credentials.

Why it matters

Exfiltration of Jira API tokens granting read access to Snowflake's engineering, security compliance, and bug bounty databases, exposing active vulnerability reports and compliance audits.

Missing authorization check

Verification of security-critical code changes (like input validation or shell commands) via a cryptographically signed authority receipt before merge.

Would PP block it?

A policy can require a named human signer for changes to workflow command construction and secret-bearing CI paths. PP would record who approved the exact diff; separate runner hardening is still required to contain exploitation.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-06-18

    The workflow change later identified as vulnerable is merged with GitHub Copilot recorded as a co-author.

  2. 2026-06-18

    Copilot's assessment marks the merged change all-clear without identifying the command-injection risk, according to Wiz's clarification.

  3. 2026-06-23

    Wiz's autonomous red-team AI agent scans the repository, detects the shell injection flaw, and executes an exploit.

  4. 2026-06-23

    The red-team agent uses the exploit to exfiltrate Jira API credentials from the CI/CD environment.

  5. 2026-08-17

    Wiz publishes the Red Agent findings and clarifies Copilot's co-author/reviewer role after public disagreement over authorship.

Technical breakdown

  • The GitHub Actions workflow interpolated attacker-controlled issue content into a shell execution context.
  • The repository history and public statements do not conclusively establish that Copilot alone authored the vulnerable code.
  • An autonomous scanner (Wiz red-team AI) evaluated the repo and mapped the input parameters to a shell command runner, identifying the injection.
  • The exploit payload was compiled and sent autonomously, executing commands inside the runner context to output env variables and extract Jira API keys.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Deploy Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
GitHub PR deployment check, CI/CD runner gate
Still needs
Traditional static analysis and peer review failed to catch the regression, and the CI/CD runner had overly permissive credential scopes.
Receipt required for
Merging AI-generated code changes affecting security controls, accessing sensitive CI/CD environment secrets

The Deploy Gate enforces that any change containing automated modifications to shell strings, execution scripts, or security boundaries requires an explicit, cryptographically signed authority receipt from a human or authorized policy engine.

Start small

Put the relevant gate at this action boundary.

This incident maps to Deploy Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Источник: Permission Protocol · AI Agent Incident Tracker · permissionprotocol.com