When AI meets CI/CD: permission bypasses, prompt injection, and what to do about it.