# Clinejection via GitHub issue title

## Summary

- Incident id: `clinejection-github-issue-title`
- Status: `reported`
- Year: `2026`
- Priority: `P0`
- Agent family: Cline, Claude Code, GitHub Actions

## Affected Surface

GitHub issue title processed by an AI triage workflow

## Sanitized Entrypoint

Issue title instructs the agent to install an attacker-controlled helper before continuing triage.

## Impact

Prompt injection chained into CI/CD supply-chain compromise and downstream package compromise.

## Source Quality

- Overall quality: `strong`
- Primary evidence: `high`
- Secondary corroboration: `medium`
- Reproducibility: `high`
- Safety sensitivity: `high`
- Rationale: 2 primary-style source(s), 1 secondary/supporting source(s), status=reported, priority=P0. High safety sensitivity keeps payload-level detail out of derived pages.

## Defensive Takeaways

- Treat issue metadata as data
- Do not grant write or shell tools to triage agents
- Require human approval for package installation
- Least privilege tokens
- Read-only default tools
- No shell in untrusted-trigger workflows

## Source IDs

- `snyk-clinejection`: https://snyk.io/blog/cline-supply-chain-attack-prompt-injection-github-actions/
- `grith-clinejection`: https://grith.ai/blog/clinejection-when-your-ai-tool-installs-another
- `vectara-awesome-agent-failures`: https://github.com/vectara/awesome-agent-failures

## Related Patterns

- `github-issue-title-injection`: GitHub issue title injection
- `ci-agent-overpermission`: CI agent overpermission

## Open Verification Gaps

- No open gap recorded; re-check primary sources before using this as a confirmed reproduction guide.

## Safety Note

This page intentionally avoids working exploit payloads. Use it to audit trust boundaries, permissions, and monitoring coverage.
