Skip to content

ci: remove Gemini issue triage (N-158) - #16

Merged
doublegate merged 2 commits into
mainfrom
fix/disable-gemini-issue-triage
Oct 7, 2026
Merged

doublegate merged 2 commits into
mainfrom
fix/disable-gemini-issue-triage

Conversation

@doublegate

Copy link
Copy Markdown
Owner

Why

Four workflow paths gave issue text from any GitHub user to the Gemini agent while it held repository credentials (app token, issues: write, id-token: write, GEMINI_API_KEY), with no check of the author's association. This is the published "PromptPwnd" pattern: a crafted issue can steer the agent into editing issues or leaking secrets. One of the scheduled triages also allowed run_shell_command(printenv) with the API keys in its environment.

Path Trigger Gate
gemini-issue-automated-triage.yml every opened issue none
gemini-issue-scheduled-triage.yml schedule, all untriaged issues none
gemini-scheduled-triage.yml schedule/PR/push, all untriaged issues none
gemini-dispatch.yml -> gemini-triage.yml opened/reopened issue none

Workflows triggered by issue events run from the default branch, so this goes to main now instead of waiting for v0.27. Tracked as N-158 in docs/audit/AUDIT-REEVALUATION-2026-10-07.md (on feat/v0.27).

Changes

  • Delete the three triage workflows and gemini-triage.yml.
  • gemini-dispatch.yml: drop the issues trigger, the triage branch of the if, the /triage command and the triage job.
  • Unchanged: review and invoke, which only run for OWNER/MEMBER/COLLABORATOR comments or for non-fork PRs.

Checks

  • gemini-dispatch.yml parses as YAML; no remaining references to the removed workflows.
  • No kernel or build changes.

🤖 Generated with Claude Code

Four paths handed issue text from any GitHub user to the Gemini agent
while it held repository credentials, with no check of who wrote the
issue: the automated triage (on every opened issue), both scheduled
triages (over every untriaged issue; one allowed `printenv` with the
API keys in its environment), and the dispatcher's issue branch into
gemini-triage.yml. This is the published "PromptPwnd" pattern (prompt
injection to exfiltrate secrets or rewrite issues).

Remove the three triage workflows and gemini-triage.yml, and drop the
`issues` trigger and the triage command from gemini-dispatch.yml.
Review and invoke, which only run for OWNER/MEMBER/COLLABORATOR
comments or non-fork PRs, are unchanged. Pull-request reviews are
also covered by the antigravity reviewer.

Issue-event workflows run from the default branch, so this lands on
main directly rather than waiting for v0.27.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 7, 2026 05:13
@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: b6a6e598-53a0-4c93-be5d-63ea6aeb480e
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Antigravity review (Gemini via Ultra)

This trivial PR removes the automated and scheduled Gemini issue triage workflows to remediate audit finding N-158.

Blocking issues

None found.

Suggestions

  • Update docs/audit/AUDIT-VERIFICATION-2026-10-05.md in this PR to mark finding N-158 as resolved, aligning with the project's documentation conventions.

Nitpicks

  • .github/workflows/gemini-dispatch.yml (lines 52-53): The checks for github.event.issue.body and github.event.issue.author_association in the dispatch job's if condition are dead code now that the issues event trigger is removed. They can be deleted.

Automated first-pass review by agy on a self-hosted runner -- not a human review.

Earlier review rounds (newest first)
Round reviewed at 2026-10-07 05:14 UTC

Antigravity review (Gemini via Ultra)

This PR removes the automated Gemini issue triage CI workflows to mitigate the risk of untrusted input reaching a privileged agent (audit N-158).

Blocking issues

None found.

Suggestions

  • .github/workflows/gemini-dispatch.yml (around line 95): With the specific /triage check removed, an issue comment containing @gemini-cli /triage will now match the fallback request.startsWith("@gemini-cli") condition and trigger a standard invoke job with /triage as context. Consider explicitly catching and rejecting /triage (e.g., by setting the command to fallthrough or logging a warning) to prevent unintended agent invocations.

Nitpicks

None.

Automated first-pass review by agy on a self-hosted runner -- not a human review.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The removed /triage command is inadvertently routed to the general Gemini invoke workflow.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Removes insecure Gemini issue-triage workflows and their dispatch integration.

Changes:

  • Deletes four automated triage workflows.
  • Removes issue triggers, triage routing, permissions, and job dependencies.
  • Preserves trusted review and invoke paths.
File Description
.github/​workflows/​gemini-triage.yml Deletes reusable triage workflow.
.github/​workflows/​gemini-scheduled-triage.yml Deletes scheduled bulk triage.
.github/​workflows/​gemini-issue-scheduled-triage.yml Deletes credentialed scheduled triage.
.github/​workflows/​gemini-issue-automated-triage.yml Deletes event-driven issue triage.
.github/​workflows/​gemini-dispatch.yml Removes issue-triggered triage dispatch.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/gemini-dispatch.yml
@codecov

codecov Bot commented Oct 7, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Without its own branch the removed /triage command matched the general
@gemini-cli prefix and ran as an invoke. Route it to fallthrough, which
posts the existing unable-to-process comment. (PR review.)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@doublegate
doublegate merged commit b745e5e into main Oct 7, 2026
19 checks passed
@doublegate
doublegate deleted the fix/disable-gemini-issue-triage branch October 7, 2026 05:56
doublegate added a commit that referenced this pull request Oct 7, 2026
Re-creating the N-56 merge while rebasing onto origin/main (PR #16)
auto-merged CHANGELOG.md without the getdents64 d_off entry. The tree is
otherwise identical to the pre-rebase head plus main's workflow removal.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants