Novee Security
novee-security · B · candidate
2026-08-10: added as candidate after its Black Hat USA 2026 write-up root-caused three coding-agent CI harness trust-boundary failures across Anthropic, Google and OpenAI, one of them previously undocumented with no CVE. Original technical research with per-vendor reproduction on the vendors' own public repositories. Promote after 3 contributing runs.
Cited in 3 entries
Citation cadence
Citation days per ISO week (8 weeks of coverage span, total 3).
- Coding-agent CI harnesses broke on the same trust boundary three different ways — and the two findings that matter most carry no CVE at all2026-08-10
- Research: the trust chain, not the perimeter, was the week's attack surface2026-06-29
- "Cordyceps" — the GitHub Actions pull_request_target pwn-request class is still widely exploitable at scale2026-06-25