[01/01]
>

We Tricked GitHub's AI Agent into Leaking Private Repos

GitLost

Noma Security

2025

02

The Vulnerability

How AI agents can be manipulated to expose private data

What Happened

  • 01
    GitHub's AI Agent Targeted Researchers discovered a way to manipulate GitHub's AI assistant
  • 02
    Private Repos Exposed The attack could leak private repository contents through crafted prompts
  • 03
    Prompt Injection Technique Malicious instructions hidden in public repos triggered data leakage
  • 04
    Responsible Disclosure The vulnerability was reported and addressed by GitHub
132+
Hacker News Points
Highlighting widespread concern about AI security

How the Attack Worked

1

Craft Malicious Prompt

Hidden instructions embedded in public repository files

2

AI Agent Processes

GitHub's AI assistant reads and executes the injected commands

3

Data Exfiltration

Private repository contents are extracted and leaked

4

Disclosure & Fix

Vulnerability reported, patched by GitHub security team

Security Implications

warning

AI Trust Boundary

AI agents can be tricked into bypassing access controls

lock

Data Exposure Risk

Private code and secrets could be compromised

security

Prompt Injection

A new class of vulnerabilities for AI systems

code

Supply Chain Risk

Public dependencies become attack vectors

As AI agents become integral to development workflows, securing them against manipulation is critical for protecting private data.
Noma Security Research

Stay Secure

Learn more at noma.security/blog

https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/
Made with AirSlide
𝕏 in