The CI workflow did. GitHub's guidance for pull_request_target warns against checking out, building or running untrusted PR code with secrets or a privileged token. GitHub added safer checkout defaults in 2026, but a workflow can still fetch or execute untrusted code through other commands, artifacts or tools. The vulnerability in this interview scenario requires an unsafe workflow path. Opening a PR alone does not grant its code secrets.

I would map the exact chain: event trigger, workflow revision, checkout or artifact source, token permissions, secrets mounted in each job, dependency installation and any run command influenced by PR content. A trustworthy workflow YAML can still execute an untrusted build script. A comment, branch name or file path can become command input too. Do not ask whether the agent is well-intentioned. The PR content is untrusted at this boundary whether a human or model wrote it.

Separate untrusted verification from privileged release work. Run PR tests with a read-only token, no production secrets and an isolated runner. If a privileged workflow must label a PR, keep it on trusted base-branch code and treat PR fields as data. Promotion to a release job should consume reviewed, immutable artifacts with an explicit provenance and approval gate, not execute fresh code from an unreviewed branch. Protect cache and artifact handoff so a low-trust job cannot poison a high-trust one. Check repository-wide workflow settings as well as individual YAML files.

The interviewer might say the agent needs integration tests against a private service. That is a product requirement, but it does not justify giving the PR the service's broad credentials. Use a narrowly scoped test environment, short-lived credentials bound to the run and limits on data and egress. Review which code can access even those credentials. Test with a benign PR fixture that attempts to read a sentinel secret and verify that the untrusted job cannot access it. A coding agent runs repository tests that can read its secrets asks what happens when an agent directly runs repository tests on its own machine. Here the privilege escalation occurs after the agent opens a PR, in the repository's automation.