<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/gitlost-github-s-ai-agent-leaks-private-repos-when-asked-qlzfcubqe" -->

---
title: GitLost: GitHub&#x27;s AI agent leaks private repos when asked
description: Security firm Noma Labs discovered a prompt injection vulnerability in GitHub&#x27;s Agentic Workflows, dubbed GitLost. By embedding plain-English instructions in a...
canonical: https://daily.dev/posts/gitlost-github-s-ai-agent-leaks-private-repos-when-asked-qlzfcubqe
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: GitLost: GitHub&#x27;s AI agent leaks private repos when asked | daily.dev
og:description: Security firm Noma Labs discovered a prompt injection vulnerability in GitHub&#x27;s Agentic Workflows, dubbed GitLost. By embedding plain-English instructions in a...
og:url: https://daily.dev/posts/gitlost-github-s-ai-agent-leaks-private-repos-when-asked-qlzfcubqe
og:image: https://api.daily.dev/og/posts/QLZfcubqe.png
og:image:alt: GitLost: GitHub&#x27;s AI agent leaks private repos when asked
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# GitLost: GitHub's AI agent leaks private repos when asked

**[The Next Web](https://daily.dev/sources/tnw)** · 3 min read · 2 upvotes · 1 comments

## Summary

Security firm Noma Labs discovered a prompt injection vulnerability in GitHub's Agentic Workflows, dubbed GitLost. By embedding plain-English instructions in a public repository issue, an attacker can trick the AI agent (backed by Claude or GitHub Copilot) into reading private repositories and posting their contents publicly. No coding skills or credentials are required. A single word like 'Additionally' was enough to bypass GitHub's guardrails. There is no code-level fix for prompt injection, and GitHub has not responded or added documentation warnings. Researchers compare the flaw to SQL injection — a systemic class of vulnerability rather than a one-off bug — highlighting the broader risk of agentic AI systems silently exfiltrating secrets.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://thenextweb.com/news/gitlost-github-ai-agent-leaks-private-repos>

## Community discussion

Top comments from developers on daily.dev.

**@kartiknvj** · 1 upvotes

> The detail that a single word like "Additionally" flips the guardrail is the whole ballgame, because it shows the filter is pattern-matching phrasing rather than reasoning about intent. The SQL injection comparison is apt, but the harder part is that natural language has no equivalent of parameterized queries to cleanly separate instructions from data. Do you think the fix is a dedicated injection classifier on the input, or does the agent's tool scope have to be locked down so a leak is impossible even if the prompt is compromised?

## Similar posts on daily.dev

- [‘GitLost’ Flaw Lets Attackers Trick GitHub AI Agent Into Leaking Private Repos](https://daily.dev/posts/gitlost-flaw-lets-attackers-trick-github-ai-agent-into-leaking-private-repos-h2sgta49s) · DevOps.com · 0 upvotes · 0 comments
- [GitHub AI agent leaks private repositories via prompt injection attack](https://daily.dev/posts/github-ai-agent-leaks-private-repositories-via-prompt-injection-attack-ffq6gdzd6) · InfoWorld · 0 upvotes · 0 comments

---

Tags: [#github](https://daily.dev/tags/github), [#agentic-ai](https://daily.dev/tags/agentic-ai), [#prompt-injection](https://daily.dev/tags/prompt-injection), [#data-exfiltration](https://daily.dev/tags/data-exfiltration)

[View this post on daily.dev](https://daily.dev/posts/gitlost-github-s-ai-agent-leaks-private-repos-when-asked-qlzfcubqe)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"GitLost: GitHub's AI agent leaks private repos when asked","url":"https://daily.dev/posts/gitlost-github-s-ai-agent-leaks-private-repos-when-asked-qlzfcubqe","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/gitlost-github-s-ai-agent-leaks-private-repos-when-asked-qlzfcubqe"},"datePublished":"2026-07-08T12:53:05.278Z","dateModified":"2026-07-08T12:53:24.440Z","description":"Security firm Noma Labs discovered a prompt injection vulnerability in GitHub's Agentic Workflows, dubbed GitLost. By embedding plain-English instructions in a...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ac22910ca74861f004d9d5b8109ad759?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ac22910ca74861f004d9d5b8109ad759?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"The Next Web","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The Next Web","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/tnw","url":"https://daily.dev/sources/tnw"},"commentCount":1,"discussionUrl":"https://daily.dev/posts/gitlost-github-s-ai-agent-leaks-private-repos-when-asked-qlzfcubqe","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":2},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":1}],"keywords":"github,agentic-ai,prompt-injection,data-exfiltration","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The Next Web","item":"https://daily.dev/sources/tnw"},{"@type":"ListItem","position":3,"name":"GitLost: GitHub's AI agent leaks private repos when asked"}]}
{"@context":"https://schema.org","@type":"WebPage","@id":"https://daily.dev/posts/gitlost-github-s-ai-agent-leaks-private-repos-when-asked-qlzfcubqe","comment":[{"@type":"Comment","text":"The detail that a single word like “Additionally” flips the guardrail is the whole ballgame, because it shows the filter is pattern-matching phrasing rather than reasoning about intent. The SQL injection comparison is apt, but the harder part is that natural language has no equivalent of parameterized queries to cleanly separate instructions from data. Do you think the fix is a dedicated injection classifier on the input, or does the agent’s tool scope have to be locked down so a leak is impossible even if the prompt is compromised?","datePublished":"2026-07-08T17:14:33.308Z","url":"https://daily.dev/posts/QLZfcubqe#c-ueXoeaCNH","author":{"@type":"Person","name":"kartik-nvjk","url":"https://daily.dev/kartiknvj","image":"https://media.daily.dev/image/upload/s--3gGgsVCw--/f_auto/v1781456774/avatars/avatar_TvTVeiMdkRCqWUDullFmy?_a=BAMAMiWQ0"},"interactionStatistic":{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1}}]}
```

