Small red team script for injecting login interception code into existing WordPress plugins
-
Updated
Jul 7, 2025 - Python
Small red team script for injecting login interception code into existing WordPress plugins
Follows an untrusted GitHub Actions value after it leaves run:, through env:, with:, step outputs and into the called action, until it dies in argv, reaches a shell, spoofs GITHUB_OUTPUT, or becomes opaque with the reason named. An injection that moved is not an injection that was fixed.
MCP server auditing .github/workflows/*.yml for supply-chain risks: script injection, leaked tokens, unpinned actions, broad permissions. Pay-per-event on Apify Store.
To associate your repository with the script-injection topic, visit your repo's landing page and select "manage topics."