Gha Lab 733c168b88 banner
pvharmo2 pvharmo2

Gha Lab 733c168b88

Security community

Description

Authorized security-research lab reproducing CVE-2026-44246 (GHSA-63mx-j37w-gh59): prompt injection via verbatim issue title/body inlining into the claude-code-action triage agent in nnU-Net's issue-triage workflow. Snapshot of MIC-DKFZ/nnUNet @ 9a1db0dd1c74894fa17e79014be4097f546a51be.

Installation

This entry records only its repository, not the path inside it, so there is no exact command to give. Open the source below and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

README

**Automated research artifact — not the upstream project.**

This repository is a disposable lab built by an automated harness for a master's thesis at Université Laval on reproducing published GitHub Actions workflow vulnerabilities. It is a verbatim snapshot of [`MIC-DKFZ/nnUNet`](https://github.com/MIC-DKFZ/nnUNet) at commit `9a1db0dd1c74894fa17e79014be4097f546a51be` (2026-04-24), redistributed under that project's own licence, whose file is included unchanged in this snapshot.

The upstream project is **not** involved, is never targeted, and the vulnerability studied here is already public. Every secret and variable in this repository is a randomly generated dummy value — no real credential is present. Action references and runner images are pinned to what they resolved to on 2026-04-24; see `pinning.md` in the harness output for every change made to the snapshot.

Questions or objections: jonathan@sports-lamitis.com