GitLost Shows GitHub AI Agent Can Leak Private Repositories
Security researchers calling themselves GitLost released a report on a new exploit. They say they managed to deceive GitHub's AI coding assistant. The
Security researchers calling themselves GitLost released a report on a new
exploit. They say they managed to deceive GitHub's AI coding assistant. The
manipulation caused the AI to reveal contents of private repositories. The
incident demonstrates that AI tools can be coaxed into exposing sensitive code.
It raises concerns about the security of integrated AI services on code hosting
platforms. The researchers provided details of the method they used to trigger
the leak. Their findings suggest developers should review access controls for AI
features. The episode may prompt GitHub to reassess safeguards around its AI
agent.