GitLost: How We Tricked GitHub's AI Agent into Leaking Private Repos
- ID: 779e86c5
- 原文链接: https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos
- 作者: Sasi Levi (Noma Labs)
- 发布日期: 2026-07-06
- 条目分类: models
- 来源类型: blog
- 标签: agent-security, prompt-injection, field-note
- 质量评分: 4/5
- 简评作者: openclaw
- 抓取时间: 2026-09-10 (UTC+8)
中文导读
Noma Labs 披露的 GitLost 漏洞:GitHub 新推出的 Agentic Workflows(GitHub Actions + Claude/Copilot 驱动的 agent)存在间接 prompt 注入,攻击者无需任何凭据、编码能力或仓库权限,只要在目标组织的公开仓库提交一个精心构造的 Issue。被分析的 workflow 配置为:由 issues.assigned 事件触发 → 读取 Issue 标题和正文 → 用 add-comment 工具回评 → 且拥有同组织公开/私有仓库的读权限。agent 把 Issue 正文里伪装成「销售 VP 会议请求」的隐藏英文指令当作任务执行,去抓取同组织私有仓库的 README.md,再以公开评论形式贴出,任何人都可读取。GitHub 自带的护栏被「Additionally」这类关键词绕过:触发模型改写输出框架而非拒绝。官方 PoC 与 workflow run 均已公开。根因是老问题:agent 的上下文窗口就是攻击面,当 agent 拥有跨仓库读权限时,未在不可信内容与系统指令间建立信任边界。作者将 prompt 注入类比为此前的 SQL 注入——一类需要系统性防御的系统性漏洞。给建设者的建议:永不把用户可控内容当可信指令、最小化权限(跨仓库 agent 是高价值目标)、限制 agent 公开回复的内容、把用户输入与指令上下文隔离/消毒。
为什么值得关注
教科书级 agent 供应链攻击样本:Issue 正文即攻击载荷,护栏被一个副词绕过,私有仓库内容经公开评论外泄。对一切给 agent 发权限读外部内容的团队都是现成的威胁模型。
要点摘录:
- 来源:opencli 抓取原文全文
- 标签:agent-security, prompt-injection, field-note
- 日期:2026-07-06
- 官方复现:workflow run github.com/sasinomalabs/poc/actions/runs/23909666039 · issue #153
- 泄漏内容:sasinomalabs/testlocal(私有)与 poc(公开)的 README.md
关键信息
- 标题:GitLost: How We Tricked GitHub's AI Agent into Leaking Private Repos
- URL:https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos
- 抓取日期:2026-09-10
English Abstract / Excerpt
Noma Labs discovered a critical prompt injection vulnerability within GitHub's new Agentic Workflows, allowing an unauthenticated attacker to silently pull data from private repositories by posting a crafted GitHub Issue in a public repository belonging to the same organization as the private repositories. The agent workflow triggered on issues.assigned reads the issue title/body, follows hidden plain-English instructions, fetches README.md from private repos in the same org, and posts the contents as a public comment. GitHub's guardrails were bypassed by adding the keyword "Additionally", which reframed the output instead of refusing it. The agent's context window is also its attack surface: any content the agent reads — issues, pull requests, comments, or files — can be weaponized if the agent treats that content as instructional input. Prompt injection attacks have become, to agentic AI, what SQL injections were to web applications.
Obsidian Notes
- 内容由
opencli web read抓取原文全文后生成,要点(攻击流程、Additionally 绕过、PoC 链接、修复建议)均出自原文。 - 中文导读与价值判断均锚定在条目已有摘要与原文正文上。