Step 1: Prompt injection via issue title. Cline had deployed an AI-powered issue triage workflow using Anthropic's claude-code-action. The workflow was configured with allowed_non_write_users: "*", meaning any GitHub user could trigger it by opening an issue. The issue title was interpolated directly into Claude's prompt via ${{ github.event.issue.title }} without sanitisation.
Пушков заявил о фатальной ошибке США в санкционной войне с Россией02:40
。关于这个话题,PDF资料提供了深入分析
Сын Алибасова задолжал налоговой более 1,8 миллиона рублей20:37,推荐阅读体育直播获取更多信息
Some smoke alarms have been designed to be ultra-sensitive. Aspirating devices, for example, constantly suck in air in order to detect even small quantities of smoke in a room. They are often used in commercial settings, including server rooms packed with expensive computer tech.,推荐阅读PDF资料获取更多信息
В Петербурге задержали иностранного гражданина за похищение ребенка. Об этом в своем Telegram-канале сообщает «78.ru».