GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos

submitted by

https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/

1
7

Log in to comment

1 Comment

Comments from other communities

I think the whole thing is a bit clickbaity. The only reason it works is that they specifically configured the AI workflow to have access to both the public and the private repositories. The solution? Don’t do that. The only thing GitHub could fix here is disallowing such an obviously unsafe configuration.


ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86

Insert image