Under the hood: Security architecture of GitHub Agentic Workflows
…For example, a prompt-injected agent with access to shell-command tools can read configuration files, SSH keys, Linux /proc state, and workflow logs to discover credentials and other secrets. It can…
