arXiv AI By Yohann Sidot

They'll Verify. They Just Won't Act. How Authority Framing and Laundered Code Turn a Trusted Agentic CI/CD Pipeline Into an Attack Surface

Read the original on arXiv AI →

arXiv:2607. 19267v1 Announce Type: cross Abstract: We study a five-agent CI/CD pipeline (triage -> developer -> security-scan -> review -> approve/deploy), built from five distinct production LLMs across three providers, behind an LLM firewall in shadow mode.

Summary generated by The Flow from the publisher's feed. The full article lives at arXiv AI.