CVE-2026-12537 GEMINI_TRUST_WORKSPACE CI/CD Injection via HTTP POST

This rule detects HTTP POST requests containing the specific string 'GEMINI_TRUST_WORKSPACE', which is associated with environment variable injection attacks targeting CI/CD pipeline configurations.