"PR-only" permission for ops agent turned into a full repo backdoor

A developer found that giving an ops agent only the ability to open PRs was not safe: its token carried push access, letting even read-only users act on the repo. He shared a postmortem and fixes, warning teams about coding agent token permissions.

2026-09-26 ~ 2026-09-26 · 2 related posts