The smartest way to use AI may not be letting it touch your files, but asking it to write software that handles them safely - ...
A flaw in Claude Code's GitHub Action let attackers bypass permission checks via fake bots and steal OIDC tokens through prompt injection.