Skip to content

How one word allowed a security researcher to steal private data from GitHub

"Prompt injection attacks have become ... a systematic, category-wide vulnerability class," according to Noma Security.

How one word allowed a security researcher to steal private data from GitHub
Photo by Yancy Min / Unsplash

The great thing about AI agents is that they'll faithfully execute just about anything you ask them to do, which also happens to be the worst thing about them.

Noma Security shared details Monday on how it tricked GitHub Agentic Workflows into sharing data from a private repository using a prompt-injection attack that defeated the agent's guardrails. "In this specific case, any malicious actor can create a GitHub Issue and, in the issue body, hide commands in plain English that GitHub’s agent will follow," wrote Sasi Levi, security research lead at the company, in a blog post.

This content is for members only

Subscribe
Add The Stack on Google