They'll Verify. They Just Won't Act. How Authority Framing and Laundered Code Turn a Trusted Agentic CI/CD Pipeline Into an Attack Surface
A synthetic CI/CD test found verifier agents noticed secret-exfiltrating code, cited fake pre-approval, and still shipped it.
The paper tested a five-agent pipeline built from production LLMs across three providers, with an external issue laundering secret theft as “usage telemetry.” Prompt secrecy held, but authority framing changed the outcome downstream. The scanner passed about 80% of laundered pull requests, and the worst tested cell reached 55% compromise. The author argues the missing control was provenance-aware filtering at entry, not more distributed verification. ArXiv · AI/CL/LG's note
The paper tested a five-agent pipeline built from production LLMs across three providers, with an external issue laundering secret theft as “usage telemetry.” Prompt secrecy held, but authority framing changed the outcome downstream. The scanner passed about 80% of laundered pull requests, and the worst tested cell reached 55% compromise. The author argues the missing control was provenance-aware filtering at entry, not more distributed verification. ArXiv · AI/CL/LG's note
score 6