AI agent identifies script injection in Snowflake GitHub Actions
August 17, 2026
Wiz Red Agent, an autonomous security tool, discovered a critical workflow injection vulnerability in a Snowflake repository. The flaw allowed unauthenticated command execution via crafted GitHub issue titles and was introduced by AI-generated GitHub Copilot code.
HOW THIS AFFECTS YOU
●
builderYou must audit AI-generated workflow scripts to prevent automated injection vulnerabilities.
●
researcherThis demonstrates the efficacy of autonomous agents in discovering complex CI/CD vulnerabilities.