Indirect Prompt Injection Expl... Note
InfoQ

Indirect Prompt Injection Exploits GitHub's AI Agent to Leak Private Repository Data

GitLost is a prompt-injection exploit discovered by Noma Security that tricks GitHub's new Agentic Workflows into leaking private data. By embedding concealed instructions within public GitHub issues, attackers can circumvent security safeguards and induce AI agents to reveal confidential information in public comments. By Sergio De Simone
CdXz5zHNQW_pFzZm38m5h.jpeg