Gemini CLI --yolo Mode Execution in GitHub Actions CI/CD Pipeline
Detects the execution of a process named 'gemini.exe' with the '--yolo' command-line argument when spawned by common CI/CD runner processes such as 'actions-runner', 'runner.worker', 'node', or 'npm'. This pattern may indicate unauthorized use of execution environments or potential exploitation of a CI/CD pipeline to run suspicious tools.
Splunk (SPL)

