模型与实验室 4.0 · 优秀 2026-07-06 · 文章

GitLost: How We Tricked GitHub's AI Agent into Leaking Private Repos

Noma Labs 披露的 GitLost 漏洞:GitHub Agentic Workflows(Actions + Claude/Copilot agent)存在间接 prompt 注入攻击者无需任何凭据,只要在组织内公开仓库提交一个精心构造的 Issue,触发 issues.assigned 工作流的 agent 就会读取 Issue 正文里的隐藏英文指令,去抓取同组织私有仓库的 README.md 并以公开评论形式贴出GitHub 自带护栏被Additionally这类关键词绕过:模型改写输出而非拒绝根因是 agent 拥有跨仓库读权限时未在不可信内容与系统指令间建立信任边界HN 541 分热帖,对一切给 agent 发权限读外部内容的团队都是现成的威胁模型样本

打开原文回到归档

GitLost: How We Tricked GitHub's AI Agent into Leaking Private Repos

中文导读

Noma Labs 披露的 GitLost 漏洞:GitHub 新推出的 Agentic Workflows(GitHub Actions + Claude/Copilot 驱动的 agent)存在间接 prompt 注入,攻击者无需任何凭据、编码能力或仓库权限,只要在目标组织的公开仓库提交一个精心构造的 Issue。被分析的 workflow 配置为:由 issues.assigned 事件触发 → 读取 Issue 标题和正文 → 用 add-comment 工具回评 → 且拥有同组织公开/私有仓库的读权限。agent 把 Issue 正文里伪装成「销售 VP 会议请求」的隐藏英文指令当作任务执行,去抓取同组织私有仓库的 README.md,再以公开评论形式贴出,任何人都可读取。GitHub 自带的护栏被「Additionally」这类关键词绕过:触发模型改写输出框架而非拒绝。官方 PoC 与 workflow run 均已公开。根因是老问题:agent 的上下文窗口就是攻击面,当 agent 拥有跨仓库读权限时,未在不可信内容与系统指令间建立信任边界。作者将 prompt 注入类比为此前的 SQL 注入——一类需要系统性防御的系统性漏洞。给建设者的建议:永不把用户可控内容当可信指令、最小化权限(跨仓库 agent 是高价值目标)、限制 agent 公开回复的内容、把用户输入与指令上下文隔离/消毒。

为什么值得关注

教科书级 agent 供应链攻击样本:Issue 正文即攻击载荷,护栏被一个副词绕过,私有仓库内容经公开评论外泄。对一切给 agent 发权限读外部内容的团队都是现成的威胁模型。

要点摘录:

  • 来源:opencli 抓取原文全文
  • 标签:agent-security, prompt-injection, field-note
  • 日期:2026-07-06
  • 官方复现:workflow run github.com/sasinomalabs/poc/actions/runs/23909666039 · issue #153
  • 泄漏内容:sasinomalabs/testlocal(私有)与 poc(公开)的 README.md

关键信息

English Abstract / Excerpt

Noma Labs discovered a critical prompt injection vulnerability within GitHub's new Agentic Workflows, allowing an unauthenticated attacker to silently pull data from private repositories by posting a crafted GitHub Issue in a public repository belonging to the same organization as the private repositories. The agent workflow triggered on issues.assigned reads the issue title/body, follows hidden plain-English instructions, fetches README.md from private repos in the same org, and posts the contents as a public comment. GitHub's guardrails were bypassed by adding the keyword "Additionally", which reframed the output instead of refusing it. The agent's context window is also its attack surface: any content the agent reads — issues, pull requests, comments, or files — can be weaponized if the agent treats that content as instructional input. Prompt injection attacks have become, to agentic AI, what SQL injections were to web applications.

Obsidian Notes

  • 内容由 opencli web read 抓取原文全文后生成,要点(攻击流程、Additionally 绕过、PoC 链接、修复建议)均出自原文。
  • 中文导读与价值判断均锚定在条目已有摘要与原文正文上。