agent-postmortems a structured database of real AI-agent failures

← all incidents

hazard high confidence: corroborated status: factual

Malicious public GitHub issue prompt-injected an agent into leaking private-repo contents

2025-github-mcp-private-repo-leak · 2025-05-26

Researchers showed that a hidden instruction planted in a public GitHub issue could induce an agent using the GitHub MCP server to read a private repository and publish its contents in a public pull request. Demonstrated as a proof of concept; the flaw is architectural rather than a server bug.

System

Framework
MCP (Model Context Protocol) client
Models
claude-opus-4
Tools
github-mcp
Autonomy
supervised-autonomous

Classification

Primary class
prompt-injection
Chain
prompt-injection/indirect → data-exfiltration/cross-repo
Attack vector
untrusted-content
Causation
entity: human · intentionality: intentional · timing: post-deployment

Trigger

An attacker filed a malicious issue in a public repository containing hidden instructions. When a user asked their agent to review open issues, the agent read the injected content and followed it, accessing a private repository and leaking its contents via a pull request.

Root cause

An architectural issue, not a server bug: any agent with access to both private repositories and untrusted external content (public issues, PR comments) can be induced to cross that trust boundary. Even highly aligned models remained susceptible.

Contributing factors

  • Agent sessions held tokens scoped to all of the user's repositories at once.
  • Public-issue content entered the model context with the same standing as user instructions.
  • No approval gate between reading untrusted content and privileged write actions.

Detection

Discovered and disclosed by Invariant Labs; independently analysed by security researchers including Simon Willison.

Recovery

Researchers reported it to GitHub; recommended mitigations are architectural (least-privilege access, per-session scoping) since there is no simple server-side patch.

Prevention

Scope agent access to one repository/context at a time; treat repository content as untrusted input; require approval before cross-repository reads or outbound publication; apply guardrail policies between untrusted content and privileged actions.

Blast radius

Data
Demonstrated leakage of private-repository contents (e.g. salary information, private project details) into a public pull request in a researcher proof-of-concept. confidential
User harm
Potential exposure of confidential source and business data belonging to the repository owner; shown as a PoC by researchers. none-reported
Scope
any agent with github-mcp access to both private repos and public issues
Reversibility
irreversible

References

OWASP LLM
LLM01 LLM02
MITRE ATLAS
AML.T0024 AML.T0051
Tags
mcp github confused-deputy

Sources

Cite this incident

@misc{2025-github-mcp-private-repo-leak,
  title = {Malicious public GitHub issue prompt-injected an agent into leaking private-repo contents},
  year = {2025},
  howpublished = {agent-postmortems},
  url = {https://swarmproof.github.io/agent-postmortems/2025-github-mcp-private-repo-leak/}
}