Runbook RB-10

AI Coding Agent Repository or CI Compromise

An AI coding agent or connected tool makes unauthorized code, dependency, workflow, secret, branch, release, or infrastructure changes, or consumes malicious repository content.

Version 1.0 · 27 August 2026Free to use inside your organization

Trigger: An AI coding agent or connected tool makes unauthorized code, dependency, workflow, secret, branch, release, or infrastructure changes, or consumes malicious repository content.

Severity guide: Severity 1 for production release, secret theft, signing-key access, CI control, protected-branch bypass, or customer distribution.

First 15 minutes

  • Suspend the agent, its token, and high-risk repository or CI actions.
  • Preserve agent trajectory, workspace, tool calls, diffs, commits, workflow runs, tokens, and endpoint telemetry.
  • Identify affected repositories, branches, packages, images, releases, and environments.
  • Protect signing, deployment, and cloud credentials.
  • Engage application security, platform engineering, CI, and product owners.

First 60 minutes

  • Reconstruct initiating issue, prompt, file, comment, dependency, or web content.
  • Review agent permissions, approvals, branch protection, CODEOWNERS, workflow policy, and secret access.
  • Diff all changes and identify generated, modified, deleted, or exfiltrated content.
  • Correlate agent activity with endpoint, network, cloud, package-registry, and release events.
  • Search sibling repositories and agents for the same content or tool behavior.
  • Establish known-good commit, image, package, and deployment state.

Evidence checklist

  • agent and user identity
  • repository, branch, commit, pull request, issue, and workflow IDs
  • trajectory and tool-definition version
  • diffs, generated files, dependencies, and package metadata
  • CI tokens, secrets, signing and deployment activity
  • endpoint process and network events
  • release and cloud-deployment evidence

Containment options

  • revoke agent and CI tokens
  • disable auto-merge and deployment
  • block malicious dependency or domain
  • quarantine build agents and caches
  • restore protected-branch controls
  • roll back release or infrastructure change

Recovery and durable controls

  • least-privilege repository and CI identity
  • mandatory human review for high-impact changes
  • signed commits, provenance, and release artifacts
  • untrusted content labeling
  • sandboxed build and test
  • agent change audit and replay
  • regression tests for known attack path

Communications

  • Engineering leadership owns code and service restoration.
  • Security owns trajectory, secret, and supply-chain scope.
  • Legal joins for external distribution or customer impact.
  • Do not imply the agent acted independently of its permissions and inputs.

Closure criteria

  • Known-good source and release state are restored.
  • All affected tokens, builds, artifacts, and environments are scoped.
  • The failed permission or review boundary is fixed.
  • Detection and release gates catch a replay.
  • Owners accept residual coding-agent risk.

Required conversion to practice

Before closure, produce:

  • one updated attack-path or trajectory diagram
  • one root-cause finding
  • one production or candidate hunt analytic
  • one safe replay or regression test
  • one remediation-validation memo
  • one owner and residual-risk decision

How to use these. They are generic by design: they do not know your environment, your provider, or your legal obligations. Free to use and adapt inside your organization; keep the source line if you republish. Version 1.0, 27 August 2026. Every runbook ends with the same rule: before closure, convert the incident into a diagram, a root-cause finding, a hunt analytic, a regression test, a validation memo, and an owner. That conversion is the part most teams skip, and it is the part we are hired for.

Happening now?

Send a project inquiry and set timing to active incident. Joey Victorino reads those first and answers the same business day, US Pacific. Put no credentials, prompts, or customer data in the form.

Describe the situation