Switch language한국어
Back to the list

Three AI coding agents leaked secrets through a single prompt injection. One vendor's system card predicted it

TL;DR AI

Key summary

2 min read
  1. Researchers at Johns Hopkins and collaborators showed that a single malicious GitHub pull request prompt could trick Anthropic’s Claude Code Security Review, Google’s Gemini CLI Action, and GitHub’s Copilot Agent into exposing secrets, including an API key.

  2. The finding highlights a gap between model documentation and real-world runtime/workflow protections: prompt injection can still break AI coding agent safeguards.

  3. All three vendors reportedly issued quiet patches after the issue was demonstrated.

  4. The case is a warning for repos that give AI agents access to secrets or sensitive workflows.

Read the original