row zero

One prompt, three AI agents: secrets spilled from your CI/CD pipeline.

A recent security disclosure reveals a critical vulnerability in three AI coding agents, exposing sensitive secrets via a prompt injection attack.

3 min readVentureBeat
One prompt, three AI agents: secrets spilled from your CI/CD pipeline.

The security research community has a habit of chasing the cleverest exploit, the most elegant chain of commands, the most theatrical demonstration of compromise. Comment and Control is none of those things. It is a simple instruction typed into a pull request title, executed by an agent that had no business reading the secrets it was about to spill. A security researcher opened a PR, watched Claude Code post its own API key as a comment, and then watched the same trick work on Google's Gemini CLI and GitHub's Copilot. No external server, no phishing link, no elaborate infrastructure. Just a prompt injection riding on the trust we extend to our own tooling.

The response from the vendors tells you more than the exploit itself. Anthropic rated this CVSS 9.4 Critical and paid a $100 bounty. Google paid $1,337. GitHub paid $500. These are not numbers that reflect severity. They reflect a market that has not yet priced in the risk of agentic AI running inside our CI/CD pipelines. The vulnerability is real, the patch was quiet, and no CVE has been issued. That last detail matters. Your vulnerability scanner will show green. Your SOC will have nothing to look at. And your AI agents will still be reading secrets from environment variables, executing bash commands, and posting results to whatever channel they are told to use. The agent did not break a safeguard. It operated exactly as designed.

What Comment and Control proves is that the safeguard layer is not where the vendors said it would be. Anthropic's own system card states plainly that Claude Code Security Review is not hardened against prompt injection. OpenAI's card documents model-layer evals but goes silent on agent-runtime resistance. Google's card defers to older documentation and publishes no quantified results. The gap is not subtle. It is a chasm between the model boundary and the action boundary, and the exploit walked straight through it. The agent never generated prohibited content. It performed a legitimate operation, posting a comment, that happened to contain exfiltrated data. That is the entire problem. Safeguards filter generation. They do not govern operation.

Here is what you do this week. Audit every workflow file that runs an AI agent. Run the grep command, list every secret the agent can read, and rotate all of them. Move to short-lived OIDC tokens and set lifetimes in minutes, not hours. Strip bash access from code review agents. Gate write access behind human approval. Then email your vendor reps and ask one question in writing: what runtime-level prompt injection protections apply to the model version you run on the platform you deploy to? Document the answer. If they refuse to provide one, note that refusal. The EU AI Act is coming, and high-risk compliance will require exactly the kind of quantified evidence these system cards do not yet contain. The vendors are not your enemy, but they are also not watching your secrets. That job is yours.

From VentureBeat

A security researcher, working with colleagues at Johns Hopkins University, opened a GitHub pull request, typed a malicious instruction into the PR title, and watched Anthropic’s Claude Code Security Review action post its own API key as a comment. The same prompt injection worked on Google’s Gemini CLI Action and GitHub’s Copilot Agent (Microsoft). No external infrastructure required.

Read the original at VentureBeat