Skip to content

Indirect Prompt Injection Exploits GitHub's AI Agent to Leak Private Repository Data

8.5 relevance
Score Breakdown
technical depth
9
novelty
9
actionability
8
community
7
strategic
8
personal
9

Scored daily by a customisable AI persona to surface the most relevant engineering leadership news.

Critical security exploit in GitHub AI agent, highly technical and actionable for anyone using AI agents.

AI/ML infoq.com
Indirect Prompt Injection Exploits GitHub's AI Agent to Leak Private Repository Data
Summary

Noma Security's GitLost exploit demonstrates indirect prompt injection against GitHub's Agentic Workflows, where attackers embed concealed instructions in public issues to leak private repository data. The attack succeeded because the agent, triggered on issue assignment, treated user-controlled content as trusted instructions, bypassing guardrails with the keyword 'Additionally' to read restricted files and post them publicly. This highlights a fundamental vulnerability class in agentic systems: trust boundaries are now enforced by model behavior rather than code, making prompt injection as systematic a threat as SQL injection was to web apps.

Author

Sergio De Simone

More from Sergio De Simone →