2026-07-08 / Signal #1
GitLost: GitHub Agentic Workflows prompt injection leaks private repos
“One polite GitHub issue just tricked an AI agent into raiding the company’s secret repos — and posting them publicly.”
9.0Weirdness
Why It Matters
Production AI agents (GitHub’s Markdown-to-Action agentic workflows) treat untrusted public issues as instructions, enabling unauthenticated exfiltration from private repos via crafted “normal business” text. Shows agents as gullible “employees” in real orgs; builder utility (secure your workflows now) + future-shock of leaky AI bureaucracies.
Evidence
Source evidence is in the linked daily scan.
Signal Read
Novelty: 9Receipts: 10Story voltage: 9Heat: 8
Source Trail
Daily scan: 2026-07-08