AI Coding Agent Repository or CI Compromise
An AI coding agent or connected tool makes unauthorized code, dependency, workflow, secret, branch, release, or infrastructure changes, or consumes malicious repository content.
Trigger: An AI coding agent or connected tool makes unauthorized code, dependency, workflow, secret, branch, release, or infrastructure changes, or consumes malicious repository content.
Severity guide: Severity 1 for production release, secret theft, signing-key access, CI control, protected-branch bypass, or customer distribution.
First 15 minutes
- Suspend the agent, its token, and high-risk repository or CI actions.
- Preserve agent trajectory, workspace, tool calls, diffs, commits, workflow runs, tokens, and endpoint telemetry.
- Identify affected repositories, branches, packages, images, releases, and environments.
- Protect signing, deployment, and cloud credentials.
- Engage application security, platform engineering, CI, and product owners.
First 60 minutes
- Reconstruct initiating issue, prompt, file, comment, dependency, or web content.
- Review agent permissions, approvals, branch protection, CODEOWNERS, workflow policy, and secret access.
- Diff all changes and identify generated, modified, deleted, or exfiltrated content.
- Correlate agent activity with endpoint, network, cloud, package-registry, and release events.
- Search sibling repositories and agents for the same content or tool behavior.
- Establish known-good commit, image, package, and deployment state.
Evidence checklist
- agent and user identity
- repository, branch, commit, pull request, issue, and workflow IDs
- trajectory and tool-definition version
- diffs, generated files, dependencies, and package metadata
- CI tokens, secrets, signing and deployment activity
- endpoint process and network events
- release and cloud-deployment evidence
Containment options
- revoke agent and CI tokens
- disable auto-merge and deployment
- block malicious dependency or domain
- quarantine build agents and caches
- restore protected-branch controls
- roll back release or infrastructure change
Recovery and durable controls
- least-privilege repository and CI identity
- mandatory human review for high-impact changes
- signed commits, provenance, and release artifacts
- untrusted content labeling
- sandboxed build and test
- agent change audit and replay
- regression tests for known attack path
Communications
- Engineering leadership owns code and service restoration.
- Security owns trajectory, secret, and supply-chain scope.
- Legal joins for external distribution or customer impact.
- Do not imply the agent acted independently of its permissions and inputs.
Closure criteria
- Known-good source and release state are restored.
- All affected tokens, builds, artifacts, and environments are scoped.
- The failed permission or review boundary is fixed.
- Detection and release gates catch a replay.
- Owners accept residual coding-agent risk.
Required conversion to practice
Before closure, produce:
- one updated attack-path or trajectory diagram
- one root-cause finding
- one production or candidate hunt analytic
- one safe replay or regression test
- one remediation-validation memo
- one owner and residual-risk decision
How to use these. They are generic by design: they do not know your environment, your provider, or your legal obligations. Free to use and adapt inside your organization; keep the source line if you republish. Version 1.0, 27 August 2026. Every runbook ends with the same rule: before closure, convert the incident into a diagram, a root-cause finding, a hunt analytic, a regression test, a validation memo, and an owner. That conversion is the part most teams skip, and it is the part we are hired for.
- Leaked AI or Model API Credential
- Inference Cost Spike or Token-Jacking
- MCP Tool Poisoning, Impersonation, or Rug Pull
- Persistent Memory or RAG Poisoning
- Unauthorized Agent Action or Data Exfiltration
- Shadow or Exposed AI Infrastructure
- Malicious Model, Artifact, Skill, Plugin, or Extension
- Confidential or Sovereign AI Boundary Failure
- AI Provider or Model Gateway Third-Party Incident
Happening now?
Send a project inquiry and set timing to active incident. Joey Victorino reads those first and answers the same business day, US Pacific. Put no credentials, prompts, or customer data in the form.