Repository navigation
ci: remove Gemini issue triage (N-158) - #16
Conversation
Four paths handed issue text from any GitHub user to the Gemini agent while it held repository credentials, with no check of who wrote the issue: the automated triage (on every opened issue), both scheduled triages (over every untriaged issue; one allowed `printenv` with the API keys in its environment), and the dispatcher's issue branch into gemini-triage.yml. This is the published "PromptPwnd" pattern (prompt injection to exfiltrate secrets or rewrite issues). Remove the three triage workflows and gemini-triage.yml, and drop the `issues` trigger and the triage command from gemini-dispatch.yml. Review and invoke, which only run for OWNER/MEMBER/COLLABORATOR comments or non-fork PRs, are unchanged. Pull-request reviews are also covered by the antigravity reviewer. Issue-event workflows run from the default branch, so this lands on main directly rather than waiting for v0.27. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configuration
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Antigravity review (Gemini via Ultra)This trivial PR removes the automated and scheduled Gemini issue triage workflows to remediate audit finding N-158. Blocking issuesNone found. Suggestions
Nitpicks
Automated first-pass review by Earlier review rounds (newest first)Round reviewed at 2026-10-07 05:14 UTCAntigravity review (Gemini via Ultra)This PR removes the automated Gemini issue triage CI workflows to mitigate the risk of untrusted input reaching a privileged agent (audit N-158). Blocking issuesNone found. Suggestions
NitpicksNone. Automated first-pass review by |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The removed /triage command is inadvertently routed to the general Gemini invoke workflow.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Removes insecure Gemini issue-triage workflows and their dispatch integration.
Changes:
- Deletes four automated triage workflows.
- Removes issue triggers, triage routing, permissions, and job dependencies.
- Preserves trusted review and invoke paths.
| File | Description |
|---|---|
.github/workflows/gemini-triage.yml |
Deletes reusable triage workflow. |
.github/workflows/gemini-scheduled-triage.yml |
Deletes scheduled bulk triage. |
.github/workflows/gemini-issue-scheduled-triage.yml |
Deletes credentialed scheduled triage. |
.github/workflows/gemini-issue-automated-triage.yml |
Deletes event-driven issue triage. |
.github/workflows/gemini-dispatch.yml |
Removes issue-triggered triage dispatch. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Without its own branch the removed /triage command matched the general @gemini-cli prefix and ran as an invoke. Route it to fallthrough, which posts the existing unable-to-process comment. (PR review.) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Re-creating the N-56 merge while rebasing onto origin/main (PR #16) auto-merged CHANGELOG.md without the getdents64 d_off entry. The tree is otherwise identical to the pre-rebase head plus main's workflow removal. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Why
Four workflow paths gave issue text from any GitHub user to the Gemini agent while it held repository credentials (app token,
issues: write,id-token: write,GEMINI_API_KEY), with no check of the author's association. This is the published "PromptPwnd" pattern: a crafted issue can steer the agent into editing issues or leaking secrets. One of the scheduled triages also allowedrun_shell_command(printenv)with the API keys in its environment.gemini-issue-automated-triage.ymlgemini-issue-scheduled-triage.ymlgemini-scheduled-triage.ymlgemini-dispatch.yml->gemini-triage.ymlWorkflows triggered by issue events run from the default branch, so this goes to
mainnow instead of waiting for v0.27. Tracked as N-158 indocs/audit/AUDIT-REEVALUATION-2026-10-07.md(onfeat/v0.27).Changes
gemini-triage.yml.gemini-dispatch.yml: drop theissuestrigger, the triage branch of theif, the/triagecommand and the triage job.Checks
gemini-dispatch.ymlparses as YAML; no remaining references to the removed workflows.🤖 Generated with Claude Code