ctipilot.ch

GMO Flatt Security Research (RyotaK)

flatt-security · B · active

https://flatt.tech/research/

researchvulnslang: enfailures: 0last fetch: 2026-07-12

AI-agent and GitHub-Actions security research. Surfaced 2026-06-05 as primary discloser of the claude-code-action [bot]-actor-bypass + prompt-injection supply-chain flaw. Candidate — promote to active after 3 runs with content contribution. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://flatt.tech/research/ (listing) then webfetch the per-post https://flatt.tech/research/posts/<slug>/ for full technical write-up. AVOID: Nothing to avoid — plain WebFetch works. Publishing cadence is low (roughly monthly), so 'recent' may be 2-3 weeks old.. | 2026-07-05 admiralty audit: B — original first-hand vulnerability research; stays active. Plain WebFetch works; cadence is ~monthly so 'recent' may be weeks old.

Cited in 2 entries

Citation cadence

Citation days per ISO week (1 weeks of coverage span, total 2).