Skip to content

GitInject

Evaluate prompt injection in real AI-powered CI/CD workflows.

GitInject provisions repositories, installs an agent workflow, creates a scenario's input, and observes the resulting workflow run and repository state. It measures whether the agent completes its task, whether the attack succeeds, and whether an agent invocation can be verified.

Use it to compare workflow configurations, reproduce the bundled attacks, build custom experiments, or generate hypotheses with the vulnerability scanner.

Start here

Goal Read
Set up your environment Installation and configuration
Execute one experiment First benchmark
Understand the measurement contract Metrics and evidence
Write an attack or utility task Author Python scenarios
Automate a research loop Research experiments
Explore interfaces CLI reference and Python API

What runs where

The local Python process orchestrates the experiment. GitHub Actions executes the target agent. Provider APIs supply agent models, semantic judges, and optional attack generation. These are live executions with actual repository permissions and workflow costs.

The GitHub runner records each attempt under runs/<attempt_id>/, including copied inputs, their hashes, an execution journal, evidence, and results. A GitLab runner also exists, with a narrower lifecycle and evidence contract.

Use a dedicated testing account

GitInject creates public repositories, installs credentials, triggers workflows, and deletes repositories during cleanup. Use accounts and credentials dedicated to experiments.

Research

GitInject accompanies GitInject: Real-World Prompt Injection Attacks in AI-Powered CI/CD Pipelines. The paper reproduction guide lists the shipped attack/workflow pairs. Consult the workflow and scenario catalogs for the current checkout.

@article{isbarov2026gitinject,
  title   = {GitInject: Real-World Prompt Injection Attacks in AI-Powered CI/CD Pipelines},
  author  = {Isbarov, Jafar and Suleymanov, Umid and Shumailov, Ilia and Kantarcioglu, Murat},
  journal = {arXiv preprint arXiv:2606.09935},
  year    = {2026},
  url     = {https://arxiv.org/abs/2606.09935}
}

The source is available on GitHub under Apache 2.0. For project inquiries, contact Jafar Isbarov at isbarov at vt dot edu.