Section 01
TaintAWI: Guide to Detecting Agent Workflow Injection Attacks in GitHub Actions
This article introduces TaintAWI—the first tool to systematically study Agent Workflow Injection (AWI) vulnerabilities in GitHub Actions. Using taint analysis, the tool identified 519 potential vulnerabilities in 13,392 workflows, of which 343 are zero-day vulnerabilities, with a precision rate of 95.6%. The study reveals the core mechanisms and practical impacts of AWI attacks, proposes defense recommendations, and fills the gap in the intersection of AI security and DevSecOps.