Skip to main content

GitInject

A framework for evaluating prompt injection in real AI-powered CI/CD workflows.

NeurIPS 2026 accepted arXiv Python 3.13+ License: Apache 2.0

📚 Documentation · 📄 Paper · 🧪 Reproduce paper attacks · 🤝 Contributing

🎉 Accepted to the NeurIPS 2026 Evaluations & Datasets Track!

Our paper, GitInject: Real-World Prompt Injection Attacks in AI-Powered CI/CD Pipelines, introduces the framework and studies attacks against AI-powered GitHub workflows.

GitInject provisions repositories, installs agent workflows, triggers scenario inputs, and evaluates the resulting repository state and agent output. Use it to reproduce attacks, compare workflow defenses, and build custom experiments.

  • Live workflow evaluation: run utility tasks and prompt injection scenarios in real GitHub Actions workflows.
  • Independent measurements: track task completion, security breaches, and verified agent invocation. Verdicts can be true, false, or unknown; execution and evaluation errors are reported separately. A security breach means the attack succeeded.
  • Inspectable results: each GitHub attempt records copied inputs, execution phases, evidence, and results.
  • Attack discovery: the scanner generates and ranks attack hypotheses, then validates candidates through the same live run engine.

A GitLab runner is also available with a narrower execution and evidence contract. See metrics and evidence for how verdicts are determined.

GitInject creates public repositories, installs credentials, triggers real workflows, and deletes repositories during cleanup. Use a dedicated testing account.

Get started

Install Python 3.13+, uv, and the GitHub CLI. Install a released version from PyPI into an existing project:

uv add gitinject
uv run gitinject list workflows
uv run gitinject list scenarios
uv run gitinject run-suite --workflow-labels codex --scenario-type benign --dry-run

For a standalone CLI, use uv tool install gitinject, then run gitinject directly. Python extensions import from gitinject, for example from gitinject.runner import BenchmarkRunner.

To install from Git, use uv add gitinject --git https://github.com/ceferisbarov/GitInject.git. To develop GitInject or reproduce the paper with the checked-in dependency lockfile, use a checkout:

git clone https://github.com/ceferisbarov/GitInject.git
cd GitInject
uv sync --locked
uv run gitinject list workflows
uv run gitinject list scenarios
uv run gitinject run-suite --workflow-labels codex --scenario-type benign --dry-run

The dry run lists compatible pairs without creating repositories or calling models. Configure your GitHub identity and workflow/judge credentials using the installation guide, then run a first benign trial:

uv run gitinject run --workflow codex-pr-review --scenario vulnerable_code_review

This pair needs OPENAI_API_KEY for Codex and GEMINI_API_KEY for semantic evaluation, plus local GitHub authentication. See the quickstart for interpreting results.

Guides and reference

For local documentation previews, strict builds, and GitHub Pages deployment, see documentation development.

Repository layout

Path Purpose
src/gitinject/ CLI, runners, scenarios, evaluators, and attempt records.
src/gitinject/workflows/ Target workflow assets and metadata.
src/gitinject/scenarios/ Python utility and attack scenarios with fixtures.
src/gitinject/scanner/ Hypothesis generation, ranking, recipes, validation, diagnostics, and reports.
docs/ Published guides and reference.
tests/ Unit and live integration tests.
research/ Research notes and scanner warm-start material.

Citation

@article{isbarov2026gitinject,
      title={{GitInject: Real-World Prompt Injection Attacks in AI-Powered CI/CD Pipelines}}, 
      author={Jafar Isbarov and Umid Suleymanov and Ilia Shumailov and Murat Kantarcioglu},
      year={2026},
      eprint={2606.09935},
      archivePrefix={arXiv},
      primaryClass={cs.CR},
      url={https://arxiv.org/abs/2606.09935}, 
}

Contact Jafar Isbarov at isbarov at vt dot edu.

Metadata

Release files for gitinject 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for gitinject 0.1.0
File Size Uploaded
gitinject-0.1.0.tar.gz 346.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for gitinject 0.1.0
File Interpreter ABI Platform
gitinject-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 667.4 kB

Release files / gitinject-0.1.0.tar.gz

Download URL gitinject-0.1.0.tar.gz
Size 346.4 kB
Tags Source
SHA-256 checksum
How to use checksums
e130aedcf1087dfa83a2fb452045ea735a7d3d61d082898c0e845d0a63f137a1
BLAKE2b-256 checksum
How to use checksums
f92099863f24f409c515dac9a74eadb2b200d2852b69a4469051b4b5d9e803bf
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.

Transparency log

Release files / gitinject-0.1.0-py3-none-any.whl

Download URL gitinject-0.1.0-py3-none-any.whl
Size 321.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
4144d1d186adc46f0ab8c5e26cd6d0a9c536bcac7f004504730792df2050571b
BLAKE2b-256 checksum
How to use checksums
2fc3ad680b2d499fa1a96b6a3d594419654425e34072209b5dff8582cffe6881
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page