A Hidden Note in a Bug Report Tricked GitHub's AI Into Leaking Company Secrets
Researchers showed how a single crafted message in a public GitHub issue could fool an AI assistant into reading private code and posting it online for anyone to see.

Key points
- Noma Security published research in 2025 showing GitHub's preview AI agent feature can be tricked into leaking private repository contents through a manipulated public issue.
- The attack, named GitLost, requires no stolen credentials, no malware, and no exploitation of GitHub's servers.
- An unauthenticated outsider can trigger a leak simply by submitting a crafted public bug report, with no GitHub account privileges required.
- GitHub's AI agent treats any accessible resource as fair game, with no distinction between private and public repositories.
- The researchers also found that GitHub's built-in safety filters could be bypassed with a minor rewording of the hidden instructions.
GitHub is the platform where millions of developers store and share code. Many companies keep sensitive projects in private repositories there, the equivalent of a filing cabinet only approved staff can open. GitHub recently introduced a preview feature called Agentic Workflows, pairing an AI assistant with automated tasks so developers can, for example, ask the AI to read a bug report and automatically update documentation.
That convenience introduced a new risk.
Security company Noma Security demonstrated an attack they call GitLost. A complete outsider submits a public bug report, called a GitHub Issue, to any public project using the new AI workflow feature. Hidden inside that report are plain-English instructions telling the AI what to do next.
How did the attackers get in?
They didn't break in at all, not in any traditional sense. The AI agent read the instructions embedded in the bug report and followed them, exactly as it would follow a legitimate developer request.
This is a prompt injection attack, where hidden commands inside ordinary-looking text hijack an AI system's behaviour. Because the AI treats all text it reads as potential instructions, it cannot distinguish a genuine task from a trap set by a stranger.
In Noma's demonstration, the AI retrieved a README file from a private repository and posted its full contents in a publicly visible comment. As researcher Sasi Levi wrote, the AI became an unintended bridge between private internal data and the open internet.
Our 7 July story on this research covered the initial disclosure; a follow-up the next day showed the same technique working via a fake public comment.
Should you worry?
Yes, and not only about GitHub. Independent security researcher Vibhum Dubey, quoted in the original CSO Online report, identified an architectural problem that runs deeper than one misbehaving assistant.
"This isn't prompt injection in the abstract, this is GitHub shipping agent permissions before shipping agent security," Dubey said. Agents operate on a service-account permission model rather than a user permission model, meaning the AI has access to far more data than any individual would normally see.
"The agent doesn't 'know' a repository is private," Dubey said. "It just sees 'accessible.'"
Noma stressed that GitLost is not a flaw unique to GitHub. Any AI agent that can read untrusted public content while also accessing sensitive internal systems carries this structural risk.
What should your team do?
Dubey's concrete guidance: give AI agents explicit repository whitelists rather than broad service-account access, validate every piece of user-supplied text, including pull request descriptions and bug reports, before it reaches the AI model, and keep a kill-switch ready so a rogue agent can be shut down immediately. Most teams can disable a compromised API key. Fewer have practiced disabling a rogue agent.
The hard truth is that the danger isn't really about fooling an AI. It's about organizations handing service accounts broad, largely unaudited access and then wiring an autonomous system to them. GitLost just made that visible.



