Malicious content in issues or pull requests can trick AI agents in CI/CD workflows into running privileged commands in an ...