We Tricked GitHub's AI Agent into Leaking Private Repos
Noma Security
2025
How AI agents can be manipulated to expose private data
Hidden instructions embedded in public repository files
GitHub's AI assistant reads and executes the injected commands
Private repository contents are extracted and leaked
Vulnerability reported, patched by GitHub security team
AI agents can be tricked into bypassing access controls
Private code and secrets could be compromised
A new class of vulnerabilities for AI systems
Public dependencies become attack vectors
As AI agents become integral to development workflows, securing them against manipulation is critical for protecting private data.Noma Security Research
Learn more at noma.security/blog