Pillar Security

Sources: Pillar Security · “My Agentic Trust Issues”

AI security vendor operating a named research team. Dan Lisichkin is one of two credited discoverers in GHSA-wpqr-6v78-jr5g, the CVSS 10.0 Gemini CLI advisory.

Pillar’s contribution is the --yolo half: the autonomy flag suppressed the fine-grained tool allowlist entirely rather than merely skipping confirmation prompts. The published chain runs from a public GitHub issue on a live Google repository through credential extraction at /proc/$PPID/environ and .git/config to repository write, obtained by dispatching a second workflow with the triage token’s actions:write permission. It is the most completely documented public exploit chain against a CI-runner coding agent catalogued here, and the only published source for the advisory’s disclosure dates. Mechanisms and timeline: the incident record.

Only this one finding is catalogued here. The firm’s product line and wider research are not assessed.