Action-path lab

See how a normal AI-assisted PR becomes a release-token path.

Start with a normal-looking PR, then trace the path from AI tool to release.yml, NPM_TOKEN, and package publish. At the end, export an Agent Action BOM, JSON action path, and evidence packet as a receipt.

Normal signal Agent opens a PR

Useful, reviewable, and usually not the control problem.

Hidden path PR changes release.yml

Now the path can influence the workflow that runs somewhere else.

Real exposure Workflow has NPM_TOKEN

That is where code assistance can become package-publish reach.

Evidence gap Approval is not always action-specific

The question becomes who approved the release-token path, not just the PR.

What does this lab export? A simulated Agent Action BOM, JSON action path, and evidence packet showing how normal AI-assisted software delivery can move through repos, CI/CD, tools, credentials, targets, approvals, and evidence gaps. It does not access your repo or upload source.