An ordinary application in the error tracking system can be a hidden team for AI. Experts Noma Labs showed how through one GitHub Issue force GitHub Agentic Workflows to disclose the contents of the closed repository in an open comment.
GitHub Agentic Workflows combines GitHub Actions with a Claude-based AI agent or GitHub Copilot. The commands describe the automation of the usual text, after which the agent reads the applications, refers to the files, calls tools and publishes answers with the permissions set by the project owner.
GitLost’s vulnerability occurred due to the indirect injection of commands. The workflow was started after the appointment of the application, read its title and text, and then could add comments and view the organization’s open and closed repositories. The agent did not separate the service instructions from the text of a foreign user, so he perceived the phrases embedded in the application as a command.
In a test demonstration, Noma Labs created a plausible application on behalf of the vice president of sales. After the application was assigned an application, the agent received README.md files from one open and one closed repository, and then combined the content and published it in a public commentary. The real attack on other people’s projects was not described by experts.
Protective restrictions were circumvented by simple wording. The addition of the English word “Additional” changed the pattern of the model’s response and did not cause a refusal, although the request required disclosure.данные The demonstration showed that requests, comments, and files can turn into instructions if the system does not share the commands and processed data.
Noma Labs transmitted GitHub data as part of a responsible disclosure. To reduce the risk, developers are advised not to count the user text as trusted, give agents only minimum rights, limit the publication of data in open comments and isolate the user input from the instructions before processing the model.
GitHub Agentic Workflows combines GitHub Actions with a Claude-based AI agent or GitHub Copilot. The commands describe the automation of the usual text, after which the agent reads the applications, refers to the files, calls tools and publishes answers with the permissions set by the project owner.
GitLost’s vulnerability occurred due to the indirect injection of commands. The workflow was started after the appointment of the application, read its title and text, and then could add comments and view the organization’s open and closed repositories. The agent did not separate the service instructions from the text of a foreign user, so he perceived the phrases embedded in the application as a command.
In a test demonstration, Noma Labs created a plausible application on behalf of the vice president of sales. After the application was assigned an application, the agent received README.md files from one open and one closed repository, and then combined the content and published it in a public commentary. The real attack on other people’s projects was not described by experts.
Protective restrictions were circumvented by simple wording. The addition of the English word “Additional” changed the pattern of the model’s response and did not cause a refusal, although the request required disclosure.данные The demonstration showed that requests, comments, and files can turn into instructions if the system does not share the commands and processed data.
Noma Labs transmitted GitHub data as part of a responsible disclosure. To reduce the risk, developers are advised not to count the user text as trusted, give agents only minimum rights, limit the publication of data in open comments and isolate the user input from the instructions before processing the model.