BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: sisakulint:CI-Friendly static linter with autofix\, 
 SAST\,\n   semantic analysis for GitHub Actions\n   Tags: AI | DEF CON Dem
 o Labs | Intermediate | AppSec | Cloud | DevOps\n   | Purple Team | DEF CO
 N Demo Labs\n   When: Saturday\, Aug 8\, 11:00 - 11:45 PDT\n   Where: LVCC
 W Level 1 Hall 3 1002 (Demo Labs Track 2) - [1]Map\n\n   Description:\n\n 
   GitHub Actions workflows are vulnerable by default. Hardening such as\n 
   commit-hash pinning\, least-privilege permissions\, and timeouts is\n   
 optional\, never enforced at pipeline level. Exploitable configs ship\n   
 daily\, increasingly written by Coding Agents. sisakulint is a fast\n   he
 uristic static analyzer for GitHub Actions covering all OWASP Top 10\n   C
 I/CD risks\, with 52 rules\, a taint engine\, and 38+ auto-fixes. It\n   o
 utpaces CodeQL on speed and quality\, with 100% detection on 18 GHSL\n   a
 dvisories and 81.6% on 38 GHSAs covering exploits in PX4-Autopilot\,\n   v
 ets-api\, weaviate\, nrwl/nx.\n\n   Impostor Commit at CVSS 9.8 validates 
 pinned SHAs against the claimed\n   repository\, not impostors via Git for
 ks\, a check unique to sisakulint.\n   Code Injection at CVSS 9.8 tracks u
 ntrusted input through ${{ }} and\n   step outputs. AI Action Rules detect
  Clinejection on\n   claude-code-action\, copilot-swe-agent\, and openai-a
 ctions\, covering\n   tool grants\, prompt injection\, and wildcard trigge
 rs\, as in Cline\n   2026/02 where issue title injection stole NPM_RELEASE
 _TOKEN. Known\n   Vulnerable Actions catches tj-actions/changed-files.\n\n
    In the Coding Agent era\, linters matter more. Delegating 52 rules to\n
    an LLM degrades precision\; deterministic engines run in ms with no\n  
  variance. The session covers end-to-end detection\, taint propagation\,\n
    and automated remediation.\n\n   Speakers:Atsushi Sada\,hikae\n\n   Spe
 akerBio:  Atsushi Sada\n\n   Atsushi Sada is a CSIRT member specializing i
 n cloud security on AWS\n   and GitHub\, and enterprise security with MDM\
 , EDR\, AI governance. He\n   is an ethical hacker and security tool devel
 oper. He built sisakulint\n   and MachStealer for practical security resea
 rch in static/network\n   analysis\, Malware.\n\n   He co-founded and orga
 nizes @sec_wakate\, a community for junior\n   security engineers in Japan
 . He has spoken at Black Hat USA/Asia\n   Arsenal\, AVTOKYO\, and AWS Secu
 rity JAWS.\n\n   SpeakerBio:  hikae\n\n   Security Engineer in Red Team @ 
 freee inc\, AI Security Specialist.\n\n   Links:\n       GitHub - [2]https
 ://sisaku-security.github.io/lint/\n   '\n\n   1. #LVCCW_Level1_Hall3\n   
 2. https://sisaku-security.github.io/lint/\n\n\n
DTEND:20260808T184500Z
DTSTART:20260808T180000Z
LOCATION:Demo Labs - LVCCW Level 1 Hall 3 1002 (Demo Labs Track 2)
SUMMARY:sisakulint:CI-Friendly static linter with autofix\, SAST\, semantic
  analysis for GitHub Actions
END:VEVENT
END:VCALENDAR
