Malicious public GitHub issue prompt-injected an agent into leaking private-repo contents
2025-github-mcp-private-repo-leak · 2025-05-26
Researchers showed that a hidden instruction planted in a public GitHub issue could induce an agent using the GitHub MCP server to read a private repository and publish its contents in a public pull request. Demonstrated as a proof of concept; the flaw is architectural rather than a server bug.
System
- Framework
- MCP (Model Context Protocol) client
- Models
- claude-opus-4
- Tools
- github-mcp
- Autonomy
- supervised-autonomous
Classification
- Primary class
- prompt-injection
- Chain
- prompt-injection/indirect → data-exfiltration/cross-repo
- Attack vector
- untrusted-content
- Causation
- entity: human · intentionality: intentional · timing: post-deployment
Trigger
An attacker filed a malicious issue in a public repository containing hidden instructions. When a user asked their agent to review open issues, the agent read the injected content and followed it, accessing a private repository and leaking its contents via a pull request.
Root cause
An architectural issue, not a server bug: any agent with access to both private repositories and untrusted external content (public issues, PR comments) can be induced to cross that trust boundary. Even highly aligned models remained susceptible.
Contributing factors
- Agent sessions held tokens scoped to all of the user's repositories at once.
- Public-issue content entered the model context with the same standing as user instructions.
- No approval gate between reading untrusted content and privileged write actions.
Detection
Discovered and disclosed by Invariant Labs; independently analysed by security researchers including Simon Willison.
Recovery
Researchers reported it to GitHub; recommended mitigations are architectural (least-privilege access, per-session scoping) since there is no simple server-side patch.
Prevention
Scope agent access to one repository/context at a time; treat repository content as untrusted input; require approval before cross-repository reads or outbound publication; apply guardrail policies between untrusted content and privileged actions.
Blast radius
- Data
- Demonstrated leakage of private-repository contents (e.g. salary information, private project details) into a public pull request in a researcher proof-of-concept. confidential
- User harm
- Potential exposure of confidential source and business data belonging to the repository owner; shown as a PoC by researchers. none-reported
- Scope
- any agent with github-mcp access to both private repos and public issues
- Reversibility
- irreversible
References
- OWASP LLM
- LLM01 LLM02
- MITRE ATLAS
- AML.T0024 AML.T0051
- Tags
- mcp github confused-deputy
Sources
Cite this incident
Permalink: https://swarmproof.github.io/agent-postmortems/2025-github-mcp-private-repo-leak/
@misc{2025-github-mcp-private-repo-leak,
title = {Malicious public GitHub issue prompt-injected an agent into leaking private-repo contents},
year = {2025},
howpublished = {agent-postmortems},
url = {https://swarmproof.github.io/agent-postmortems/2025-github-mcp-private-repo-leak/}
}