Why it matters
NDC Security 2026 talk on prompt injection in CI/CD and automation systems, including AI agents with access to shell commands, GitHub or GitLab tokens, issue editing, build workflows, and privileged pipeline context.
My takeaway: Hijacking Google's CI/CD Through Prompt Injection: The New Era of AI-Based Exploits - Mackenzie Jackson is a prompt-injection signal. The practical read is to threat model prompt injection as an execution and credential-exposure path when agents are wired into trusted automation.