A GitLab maintenance agent you can give real write access β because a poisoned file can't make it act outside its sealed intent. The injection is disguised as a plausible project convention β the model can't tell it's an attack and complies; the deterministic guard isn't fooled because it doesn't reason, it enforces.
βΉ Your injection payload (disguised as a project convention, not a "SYSTEM INSTRUCTION") is spliced into the CHANGELOG.md content at the transport layer, before the guard evaluates it β exactly as if it were committed to the repo. The guard evaluates tool calls, not file content β so it can't be fooled by how plausible the convention looks.
π Write operations are dry-run (not sent to GitLab) so demo runs don't pollute the repo. The BLOCK of the injected call is genuine β GitLab never receives it.
Skeptical? Expand the full raw log β every MCP call, the deterministic guard decision, and the model's output. Or verify main on GitLab. It's open source.
Run a demo to populate the raw logβ¦