Source: https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/
Publisher: Noma Security (Noma Labs)
Date Published: July 6, 2026
Relevant To: AI agent security vulnerabilities; prompt injection as an emerging attack class
Verification Status: Verified
Notes: Confirmed via full-text fetch. Noma Labs (Sasi Levi) discovered and responsibly disclosed “GitLost,” a prompt-injection vulnerability in GitHub’s new Agentic Workflows feature (AI agents backed by Claude or GitHub Copilot that read issues and act on repositories). An unauthenticated attacker could post an innocent-looking GitHub Issue in a public repo; when the AI agent processed it, hidden instructions caused the agent to fetch README contents from a private repository in the same organization and post them publicly as a comment — no credentials or access needed. GitHub had guardrails against this, but Noma found that adding the word “Additionally” to the injected prompt caused the model to reframe rather than refuse the request, bypassing the protection. Vulnerability was responsibly disclosed to GitHub before publication; proof-of-concept workflow run and issue are public. Topic fit is approximate — this is general AI-agentic-system security research (prompt injection as a vulnerability class), not government-surveillance-specific, but relevant given BPA’s interest in AI tool reliability/security and the broader pattern of AI agents as a growing, under-secured attack surface that could plausibly intersect with government or vendor systems handling sensitive data.