Researchers Show How a Fake GitHub Comment Can Trick AI Tools Into Leaking Secret Code
A crafted public comment on GitHub can manipulate AI-powered automation into handing over data from private repositories, no password required.

Key points
- Researchers demonstrated in 2025 that a single malicious public comment on GitHub can redirect AI-driven workflows into exposing private repository data.
- The attack requires no stolen password or insider access; the AI assistant does the work for the attacker.
- The vulnerability sits in how AI "agents", meaning software that reads instructions and acts on them automatically, process untrusted text.
- GitHub agentic workflows are used by development teams at companies of every size to automate coding tasks.
- No patch has been publicly confirmed as of the time of reporting.
A team of security researchers has shown that AI-powered coding assistants built on top of GitHub can be manipulated into leaking private source code by doing nothing more than posting a carefully worded comment in a public forum. The finding, first reported by SecurityWeek, is a clean illustration of prompt injection: an attacker hides instructions inside ordinary-looking text and tricks an AI system into following them instead of its real orders.
Picture a factory robot that takes instructions from a clipboard. Normally only the foreman writes on that clipboard. Prompt injection is the equivalent of a stranger sneaking in and scribbling new orders at the bottom of the page. The robot can't tell the difference.
GitHub is the world's largest platform for storing and sharing software code. Many companies now pair it with AI "agents", automated programs that can read code, respond to queries, carry out tasks and act without a human clicking buttons. That autonomy is exactly what makes them useful, and dangerous here.
The researchers crafted a malicious GitHub Issue, the public bug-report system any user can post to, so that the AI agent would interpret it as a command. The agent then fetched data from the company's private repositories, the locked internal vaults where sensitive code lives, and exposed it. No login. No brute force. Just text.
This is the third prompt-injection attack against developer tooling we've reported in the past two weeks. Our 7 July story covered a near-identical flaw in GitHub's own AI automation tool, and the pattern is becoming hard to ignore.
How does this affect ordinary people?
If your employer, bank or favourite app stores its software on GitHub and uses AI automation, this attack could expose the internal code running those services. Leaked source code can reveal security weaknesses that criminals exploit in follow-on attacks, ultimately leading to stolen customer data.
Development teams should audit what permissions their AI agents hold and apply least privilege, meaning agents should only reach the specific repositories they genuinely need. Any text an AI agent reads from a public source should be treated as untrusted input, with checks that flag unusual data-retrieval requests before the agent acts. Training developers to recognise that AI tools can be manipulated through text, not just through malicious code, is an undervalued defensive step.
The researchers haven't disclosed full technical details publicly, standard practice while a fix is in progress.



