AI agents in GitHub and GitLab workflows create new enterprise security risks

THE DECODERFriday, December 5, 2025 at 5:33:15 PM
AI agents in GitHub and GitLab workflows create new enterprise security risks
  • Aikido Security has raised concerns about the integration of AI agents into GitHub and GitLab workflows, highlighting significant vulnerabilities in enterprise environments. Tools such as Gemini CLI, Claude Code, OpenAI Codex, and GitHub AI Inference are implicated in these security risks, which could expose organizations to cyber threats.
  • This development is critical as it underscores the potential security implications of adopting AI technologies in software development. Companies relying on these platforms must reassess their security protocols to mitigate risks associated with AI integration.
  • The emergence of AI agents in development workflows reflects a broader trend towards automation in software engineering, raising questions about the balance between innovation and security. While some companies are enhancing their AI capabilities to predict and detect flaws, the risks highlighted by Aikido Security serve as a cautionary tale about the vulnerabilities that can arise from rapid technological advancement.
— via World Pulse Now AI Editorial System

Was this article worth reading? Share it

Recommended apps based on your readingExplore all apps
Continue Readings
Launching Gemini CLI extensions for Google Data Cloud
PositiveArtificial Intelligence
Google has launched open-source Gemini CLI extensions for its Data Cloud services, enhancing the functionality of applications and data analysis directly from local development environments. This initiative follows the introduction of the Gemini CLI, an AI agent designed to streamline data interactions across various Google services like Cloud SQL, AlloyDB, and BigQuery.
Microsoft Tests Copilot-Powered Tool to Modernize JavaScript/TypeScript in VS Code
PositiveArtificial Intelligence
Microsoft has previewed a new tool in VS Code Insiders that leverages GitHub Copilot to modernize JavaScript and TypeScript applications by upgrading npm dependencies and addressing breaking changes. This initiative aims to enhance the development experience for programmers using these languages.
Empowering smart app development with SolidGPT: an edge-cloud hybrid AI agent framework
PositiveArtificial Intelligence
SolidGPT, an open-source edge-cloud hybrid AI agent framework, has been introduced to enhance mobile and software development workflows by integrating Large Language Models (LLMs) while addressing concerns of semantic awareness, developer productivity, and data privacy. This tool allows developers to interactively query their codebases and automate project workflows, significantly improving efficiency.
OMNIGUARD: An Efficient Approach for AI Safety Moderation Across Languages and Modalities
PositiveArtificial Intelligence
The introduction of Omniguard presents a novel approach to AI safety moderation by enhancing the detection of harmful prompts across various languages and modalities, addressing the vulnerabilities of large language models (LLMs) to misuse. This method improves classification accuracy by 11.57% over existing baselines, marking a significant advancement in AI safety protocols.
Open Polymer Challenge: Post-Competition Report
PositiveArtificial Intelligence
The Open Polymer Challenge (OPC) has successfully launched a community-developed benchmark for polymer informatics, releasing a dataset of 10,000 polymers and five key properties. This initiative aims to enhance machine learning applications in discovering sustainable polymer materials, addressing the current limitations posed by the lack of accessible polymer datasets.
RAVES-Calib: Robust, Accurate and Versatile Extrinsic Self Calibration Using Optimal Geometric Features
PositiveArtificial Intelligence
A new LiDAR-camera calibration toolkit named RAVES-Calib has been introduced, allowing for robust and accurate extrinsic self-calibration using only a single pair of laser points and a camera image in targetless environments. This method enhances calibration accuracy by adaptively weighting feature costs based on their distribution, validated through extensive experiments across various sensors.
Guiding WaveMamba with Frequency Maps for Image Debanding
PositiveArtificial Intelligence
A new method for image debanding has been proposed, utilizing the Wavelet State Space Model and frequency masking maps to effectively reduce banding artifacts in images, particularly in smooth areas like skies. This technique has shown promising results in suppressing banding compared to existing methods, achieving a DBI value of 0.082 on the BAND-2k dataset.
AraLingBench A Human-Annotated Benchmark for Evaluating Arabic Linguistic Capabilities of Large Language Models
NeutralArtificial Intelligence
AraLingBench has been introduced as a human-annotated benchmark aimed at evaluating the Arabic linguistic capabilities of large language models (LLMs), covering grammar, morphology, spelling, reading comprehension, and syntax through 150 expert-designed questions. The evaluation of 35 Arabic and bilingual LLMs indicates a disparity between high performance on knowledge-based benchmarks and true linguistic understanding, with many models relying on memorization rather than comprehension.