Repo-Injection: When Your AI Code Reviewer Gets Hacked
Developers rely on AI to review third-party code before it reaches production. Repo-Injection shows how that workflow can be manipulated, allowing a malicious package to both execute and influence the outcome of its own review.