{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2026:2JYJ3OZLNC5ZBEX6I7NNB44MXH","short_pith_number":"pith:2JYJ3OZL","canonical_record":{"source":{"id":"2605.05969","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-07T10:16:26Z","cross_cats_sorted":["cs.SE"],"title_canon_sha256":"bbf0f0e668bb43b3ad008ee008f0f49e6806b757b8a6b6e463a24af411259a95","abstract_canon_sha256":"0b0d9a3f689e63ee435f40be3fa41ebfec9104d952d84365b52f9fd07278bdc1"},"schema_version":"1.0"},"canonical_sha256":"d2709dbb2b68bb9092fe47dad0f38cb9e8c30a62a03edec066fed697bb8b1463","source":{"kind":"arxiv","id":"2605.05969","version":2},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.05969","created_at":"2026-07-10T01:19:00Z"},{"alias_kind":"arxiv_version","alias_value":"2605.05969v2","created_at":"2026-07-10T01:19:00Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.05969","created_at":"2026-07-10T01:19:00Z"},{"alias_kind":"pith_short_12","alias_value":"2JYJ3OZLNC5Z","created_at":"2026-07-10T01:19:00Z"},{"alias_kind":"pith_short_16","alias_value":"2JYJ3OZLNC5ZBEX6","created_at":"2026-07-10T01:19:00Z"},{"alias_kind":"pith_short_8","alias_value":"2JYJ3OZL","created_at":"2026-07-10T01:19:00Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2026:2JYJ3OZLNC5ZBEX6I7NNB44MXH","target":"record","payload":{"canonical_record":{"source":{"id":"2605.05969","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-07T10:16:26Z","cross_cats_sorted":["cs.SE"],"title_canon_sha256":"bbf0f0e668bb43b3ad008ee008f0f49e6806b757b8a6b6e463a24af411259a95","abstract_canon_sha256":"0b0d9a3f689e63ee435f40be3fa41ebfec9104d952d84365b52f9fd07278bdc1"},"schema_version":"1.0"},"canonical_sha256":"d2709dbb2b68bb9092fe47dad0f38cb9e8c30a62a03edec066fed697bb8b1463","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-10T01:19:00.438806Z","signature_b64":"/KmMxdFt0QYXKig+DhWBzEYYH7wz4ZELz2SObDnk7tZQjlX0eMfHNThjQvdaGVfsIKM9mK3C4ZgiS7dxXp73Cw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"d2709dbb2b68bb9092fe47dad0f38cb9e8c30a62a03edec066fed697bb8b1463","last_reissued_at":"2026-07-10T01:19:00.438348Z","signature_status":"signed_v1","first_computed_at":"2026-07-10T01:19:00.438348Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2605.05969","source_version":2,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-10T01:19:00Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"OZGVhmcVTDCew+BdtOV0VoF8fTrxTwt45Tg9y+m1P2sMIKmKwtOBhBFYA2N9mptm6G82M1mnnOFgkoZU34rJBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-05T01:29:29.553634Z"},"content_sha256":"d4a1ffd4ca0b6facbd25f1af8445a227a3a021a606199ff07beedab5d0ba1b5a","schema_version":"1.0","event_id":"sha256:d4a1ffd4ca0b6facbd25f1af8445a227a3a021a606199ff07beedab5d0ba1b5a"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2026:2JYJ3OZLNC5ZBEX6I7NNB44MXH","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"Heimdallr: Characterizing and Detecting LLM-Induced Security Risks in GitHub CI Workflows","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"Integrating LLMs into GitHub CI workflows creates exploitable security risks that can be detected through graph-based analysis of workflow inputs and outputs.","cross_cats":["cs.SE"],"primary_cat":"cs.CR","authors_text":"Bonan Ruan, Chuqi Zhang, Jiahao Liu, Jun Zeng, Yeqi Fu, Zhenkai Liang","submitted_at":"2026-05-07T10:16:26Z","abstract_excerpt":"GitHub Continuous Integration (CI) workflows increasingly integrate Large Language Models (LLMs) to automate review, triage, content generation, and repository maintenance. This creates a new attack surface: externally controllable workflow inputs can shape LLM prompts and outputs, which may in turn affect security decisions, repository state, or privileged execution. Although LLM security and CI security have each been studied extensively, their intersection remains underexplored. In this paper, we present the first study of LLM-induced security risks in GitHub CI workflows. We characterize t"},"claims":{"count":4,"items":[{"kind":"strongest_claim","text":"Evaluated on 300 manually annotated unique workflows, Heimdallr achieves high accuracy on LLM-node identification (F1~=~0.994), triggerability classification (99.8%), and threat-vector detection (micro-average F1~=~0.917).","source":"verdict.strongest_claim","status":"machine_extracted","claim_id":"C1","attestation":"unclaimed"},{"kind":"weakest_assumption","text":"The 300 manually annotated workflows provide unbiased and complete ground truth for evaluating LLM-node identification, triggerability, and threat-vector detection across the taxonomy of risks.","source":"verdict.weakest_assumption","status":"machine_extracted","claim_id":"C2","attestation":"unclaimed"},{"kind":"one_line_summary","text":"Heimdallr detects LLM-induced security risks in GitHub CI workflows by normalizing them into an LLM-Workflow Property Graph and combining triggerability analysis with LLM-assisted dataflow summarization, achieving over 0.91 F1 on threat detection in evaluation.","source":"verdict.one_line_summary","status":"machine_extracted","claim_id":"C3","attestation":"unclaimed"},{"kind":"headline","text":"Integrating LLMs into GitHub CI workflows creates exploitable security risks that can be detected through graph-based analysis of workflow inputs and outputs.","source":"verdict.pith_extraction.headline","status":"machine_extracted","claim_id":"C4","attestation":"unclaimed"}],"snapshot_sha256":"bb17e65ed73a6a96901192dc5caf31f3e200ae4c8b3c24e70edc456ab05efe4d"},"source":{"id":"2605.05969","kind":"arxiv","version":2},"verdict":{"id":"278664fd-03d5-42d4-a6b6-25aac1bf94ec","model_set":{"reader":"grok-4.3"},"created_at":"2026-05-08T09:25:44.892411Z","strongest_claim":"Evaluated on 300 manually annotated unique workflows, Heimdallr achieves high accuracy on LLM-node identification (F1~=~0.994), triggerability classification (99.8%), and threat-vector detection (micro-average F1~=~0.917).","one_line_summary":"Heimdallr detects LLM-induced security risks in GitHub CI workflows by normalizing them into an LLM-Workflow Property Graph and combining triggerability analysis with LLM-assisted dataflow summarization, achieving over 0.91 F1 on threat detection in evaluation.","pipeline_version":"pith-pipeline@v0.9.0","weakest_assumption":"The 300 manually annotated workflows provide unbiased and complete ground truth for evaluating LLM-node identification, triggerability, and threat-vector detection across the taxonomy of risks.","pith_extraction_headline":"Integrating LLMs into GitHub CI workflows creates exploitable security risks that can be detected through graph-based analysis of workflow inputs and outputs."},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.05969/integrity.json","findings":[],"available":true,"detectors_run":[{"name":"claim_evidence","ran_at":"2026-05-20T13:22:04.380556Z","status":"completed","version":"1.0.0","findings_count":0},{"name":"ai_meta_artifact","ran_at":"2026-05-20T08:39:39.411904Z","status":"completed","version":"1.0.0","findings_count":0},{"name":"doi_title_agreement","ran_at":"2026-05-19T19:31:19.292052Z","status":"completed","version":"1.0.0","findings_count":0},{"name":"doi_compliance","ran_at":"2026-05-19T13:06:16.288155Z","status":"completed","version":"1.0.0","findings_count":0}],"snapshot_sha256":"5540309e516a6f15c970ad66c51c6078c723fbf75b44d6613d5fcaf2c49f2a28"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":"278664fd-03d5-42d4-a6b6-25aac1bf94ec"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-10T01:19:00Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"2ByR89qbwFfWz4DbgyX9kLkdM4qRkStB6YFoVNRPKN0jLKngfuW3qoRBRu7BH8pJtW9LxjiWCGR1vW6jPqYEBw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-05T01:29:29.555059Z"},"content_sha256":"1dd75b41e16ff8ad8c32c68b170cd6919e789d6bea955292c659345f3efc3d02","schema_version":"1.0","event_id":"sha256:1dd75b41e16ff8ad8c32c68b170cd6919e789d6bea955292c659345f3efc3d02"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/2JYJ3OZLNC5ZBEX6I7NNB44MXH/bundle.json","state_url":"https://pith.science/pith/2JYJ3OZLNC5ZBEX6I7NNB44MXH/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/2JYJ3OZLNC5ZBEX6I7NNB44MXH/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-08-05T01:29:29Z","links":{"resolver":"https://pith.science/pith/2JYJ3OZLNC5ZBEX6I7NNB44MXH","bundle":"https://pith.science/pith/2JYJ3OZLNC5ZBEX6I7NNB44MXH/bundle.json","state":"https://pith.science/pith/2JYJ3OZLNC5ZBEX6I7NNB44MXH/state.json","well_known_bundle":"https://pith.science/.well-known/pith/2JYJ3OZLNC5ZBEX6I7NNB44MXH/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2026:2JYJ3OZLNC5ZBEX6I7NNB44MXH","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"0b0d9a3f689e63ee435f40be3fa41ebfec9104d952d84365b52f9fd07278bdc1","cross_cats_sorted":["cs.SE"],"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-07T10:16:26Z","title_canon_sha256":"bbf0f0e668bb43b3ad008ee008f0f49e6806b757b8a6b6e463a24af411259a95"},"schema_version":"1.0","source":{"id":"2605.05969","kind":"arxiv","version":2}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2605.05969","created_at":"2026-07-10T01:19:00Z"},{"alias_kind":"arxiv_version","alias_value":"2605.05969v2","created_at":"2026-07-10T01:19:00Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.05969","created_at":"2026-07-10T01:19:00Z"},{"alias_kind":"pith_short_12","alias_value":"2JYJ3OZLNC5Z","created_at":"2026-07-10T01:19:00Z"},{"alias_kind":"pith_short_16","alias_value":"2JYJ3OZLNC5ZBEX6","created_at":"2026-07-10T01:19:00Z"},{"alias_kind":"pith_short_8","alias_value":"2JYJ3OZL","created_at":"2026-07-10T01:19:00Z"}],"graph_snapshots":[{"event_id":"sha256:1dd75b41e16ff8ad8c32c68b170cd6919e789d6bea955292c659345f3efc3d02","target":"graph","created_at":"2026-07-10T01:19:00Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":4,"items":[{"attestation":"unclaimed","claim_id":"C1","kind":"strongest_claim","source":"verdict.strongest_claim","status":"machine_extracted","text":"Evaluated on 300 manually annotated unique workflows, Heimdallr achieves high accuracy on LLM-node identification (F1~=~0.994), triggerability classification (99.8%), and threat-vector detection (micro-average F1~=~0.917)."},{"attestation":"unclaimed","claim_id":"C2","kind":"weakest_assumption","source":"verdict.weakest_assumption","status":"machine_extracted","text":"The 300 manually annotated workflows provide unbiased and complete ground truth for evaluating LLM-node identification, triggerability, and threat-vector detection across the taxonomy of risks."},{"attestation":"unclaimed","claim_id":"C3","kind":"one_line_summary","source":"verdict.one_line_summary","status":"machine_extracted","text":"Heimdallr detects LLM-induced security risks in GitHub CI workflows by normalizing them into an LLM-Workflow Property Graph and combining triggerability analysis with LLM-assisted dataflow summarization, achieving over 0.91 F1 on threat detection in evaluation."},{"attestation":"unclaimed","claim_id":"C4","kind":"headline","source":"verdict.pith_extraction.headline","status":"machine_extracted","text":"Integrating LLMs into GitHub CI workflows creates exploitable security risks that can be detected through graph-based analysis of workflow inputs and outputs."}],"snapshot_sha256":"bb17e65ed73a6a96901192dc5caf31f3e200ae4c8b3c24e70edc456ab05efe4d"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[{"findings_count":0,"name":"claim_evidence","ran_at":"2026-05-20T13:22:04.380556Z","status":"completed","version":"1.0.0"},{"findings_count":0,"name":"ai_meta_artifact","ran_at":"2026-05-20T08:39:39.411904Z","status":"completed","version":"1.0.0"},{"findings_count":0,"name":"doi_title_agreement","ran_at":"2026-05-19T19:31:19.292052Z","status":"completed","version":"1.0.0"},{"findings_count":0,"name":"doi_compliance","ran_at":"2026-05-19T13:06:16.288155Z","status":"completed","version":"1.0.0"}],"endpoint":"/pith/2605.05969/integrity.json","findings":[],"snapshot_sha256":"5540309e516a6f15c970ad66c51c6078c723fbf75b44d6613d5fcaf2c49f2a28","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"GitHub Continuous Integration (CI) workflows increasingly integrate Large Language Models (LLMs) to automate review, triage, content generation, and repository maintenance. This creates a new attack surface: externally controllable workflow inputs can shape LLM prompts and outputs, which may in turn affect security decisions, repository state, or privileged execution. Although LLM security and CI security have each been studied extensively, their intersection remains underexplored. In this paper, we present the first study of LLM-induced security risks in GitHub CI workflows. We characterize t","authors_text":"Bonan Ruan, Chuqi Zhang, Jiahao Liu, Jun Zeng, Yeqi Fu, Zhenkai Liang","cross_cats":["cs.SE"],"headline":"Integrating LLMs into GitHub CI workflows creates exploitable security risks that can be detected through graph-based analysis of workflow inputs and outputs.","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-07T10:16:26Z","title":"Heimdallr: Characterizing and Detecting LLM-Induced Security Risks in GitHub CI Workflows"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.05969","kind":"arxiv","version":2},"verdict":{"created_at":"2026-05-08T09:25:44.892411Z","id":"278664fd-03d5-42d4-a6b6-25aac1bf94ec","model_set":{"reader":"grok-4.3"},"one_line_summary":"Heimdallr detects LLM-induced security risks in GitHub CI workflows by normalizing them into an LLM-Workflow Property Graph and combining triggerability analysis with LLM-assisted dataflow summarization, achieving over 0.91 F1 on threat detection in evaluation.","pipeline_version":"pith-pipeline@v0.9.0","pith_extraction_headline":"Integrating LLMs into GitHub CI workflows creates exploitable security risks that can be detected through graph-based analysis of workflow inputs and outputs.","strongest_claim":"Evaluated on 300 manually annotated unique workflows, Heimdallr achieves high accuracy on LLM-node identification (F1~=~0.994), triggerability classification (99.8%), and threat-vector detection (micro-average F1~=~0.917).","weakest_assumption":"The 300 manually annotated workflows provide unbiased and complete ground truth for evaluating LLM-node identification, triggerability, and threat-vector detection across the taxonomy of risks."}},"verdict_id":"278664fd-03d5-42d4-a6b6-25aac1bf94ec"}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:d4a1ffd4ca0b6facbd25f1af8445a227a3a021a606199ff07beedab5d0ba1b5a","target":"record","created_at":"2026-07-10T01:19:00Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"0b0d9a3f689e63ee435f40be3fa41ebfec9104d952d84365b52f9fd07278bdc1","cross_cats_sorted":["cs.SE"],"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.CR","submitted_at":"2026-05-07T10:16:26Z","title_canon_sha256":"bbf0f0e668bb43b3ad008ee008f0f49e6806b757b8a6b6e463a24af411259a95"},"schema_version":"1.0","source":{"id":"2605.05969","kind":"arxiv","version":2}},"canonical_sha256":"d2709dbb2b68bb9092fe47dad0f38cb9e8c30a62a03edec066fed697bb8b1463","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"d2709dbb2b68bb9092fe47dad0f38cb9e8c30a62a03edec066fed697bb8b1463","first_computed_at":"2026-07-10T01:19:00.438348Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-10T01:19:00.438348Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"/KmMxdFt0QYXKig+DhWBzEYYH7wz4ZELz2SObDnk7tZQjlX0eMfHNThjQvdaGVfsIKM9mK3C4ZgiS7dxXp73Cw==","signature_status":"signed_v1","signed_at":"2026-07-10T01:19:00.438806Z","signed_message":"canonical_sha256_bytes"},"source_id":"2605.05969","source_kind":"arxiv","source_version":2}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:d4a1ffd4ca0b6facbd25f1af8445a227a3a021a606199ff07beedab5d0ba1b5a","sha256:1dd75b41e16ff8ad8c32c68b170cd6919e789d6bea955292c659345f3efc3d02"],"state_sha256":"8225d7a71d832939a2afb35aa2584535b0ec1db438e391adb927113bb2500e82"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"GlTK72+373pUV+1o/Hd02Fl61LpTiy1iPjAlcyhw6RT9o3HSPxd5AqAzJcfSJs3UdQ3snhP5DTeYFPt3MGj7Cg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-08-05T01:29:29.572157Z","bundle_sha256":"6b1223adabb9096617ae923eab091453e515f08bb3fdc9cdf279bf672f578137"}}