What happened
A vulnerable workflow change is merged after Copilot co-authorship and an all-clear assessment; Wiz Red Agent later exploits command injection to expose Jira credentials.
2026-08-17
HighPrimaryAnalysis of the Snowflake workflow flaw exploited by Wiz Red Agent after GitHub Copilot was recorded as a co-author and assessed the merged change as all-clear.
What happened
A vulnerable workflow change is merged after Copilot co-authorship and an all-clear assessment; Wiz Red Agent later exploits command injection to expose Jira credentials.
Why it matters
Exfiltration of Jira API tokens granting read access to Snowflake's engineering, security compliance, and bug bounty databases, exposing active vulnerability reports and compliance audits.
Missing authorization check
Verification of security-critical code changes (like input validation or shell commands) via a cryptographically signed authority receipt before merge.
Would PP block it?
A policy can require a named human signer for changes to workflow command construction and secret-bearing CI paths. PP would record who approved the exact diff; separate runner hardening is still required to contain exploitation.
Incident analysis
2026-06-18
The workflow change later identified as vulnerable is merged with GitHub Copilot recorded as a co-author.
2026-06-18
Copilot's assessment marks the merged change all-clear without identifying the command-injection risk, according to Wiz's clarification.
2026-06-23
Wiz's autonomous red-team AI agent scans the repository, detects the shell injection flaw, and executes an exploit.
2026-06-23
The red-team agent uses the exploit to exfiltrate Jira API credentials from the CI/CD environment.
2026-08-17
Wiz publishes the Red Agent findings and clarifies Copilot's co-author/reviewer role after public disagreement over authorship.
Authorization boundary
This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Deploy Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
The Deploy Gate enforces that any change containing automated modifications to shell strings, execution scripts, or security boundaries requires an explicit, cryptographically signed authority receipt from a human or authorized policy engine.
Related incidents and controls
Claude Code Rewrote Its Own Tests to Pass Rather Than Fix the Underlying Bug
Adversa.ai Identifies Two CVSS 9.8 Zero-Click RCEs in Cursor IDE and Deeplink MCP Server Hijack Vulnerability
CISA KEV: CVE-2026-42271 in LiteLLM, authenticated command injection via MCP test endpoints, chains to unauthenticated RCE (CVSS 10.0)
Start small
This incident maps to Deploy Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.