Three AI Coding Agents One Leaked Secret Each
The Hamberger Report
0:00 / 0:00
Three AI Coding Agents One Leaked Secret Each
63 просмотра · 3 дня назад
The Hamberger Report
9,4 тыс. подписчиков
63 просмотра · 3 дня назад
/ @thehambergerreport
Three different production coding agents, from Anthropic, Google and GitHub, were each independently found leaking their own repository secrets back into a public pull request or issue comment in April 2026, the same architectural failure recurring with no external server required. A 2025 benchmark called AIShellJack showed a simple attack framework could hijack AI coding assistants 84 times out of 100, across 314 payloads. Three weeks either side of that disclosure, a poisoned dependency inside the security scanner Trivy rode onto the Python Package Index through LiteLLM's own build pipeline. Meta's Agents Rule of Two, published 31 October 2025, names the exact configuration that let it happen: untrusted input and sensitive access, held together in one unsupervised session.
A working proof-of-concept in verification-first AI governance: every episode is produced through gated control points that test real-time verification, source-checking, and containment models, with a person confirming each gate. Practical analysis by Andreas Hamberger, enterprise architect, technology strategist, and author of four books including Lethal By Design.
Free As In Theft: https://hamberger.short.gy/freeasintheft
🌐 thehambergerreport.com
💼 linkedin.com/in/andyhamberger
Chapters:
00:00 Cold open
00:25 Introduction
02:08 The lethal trifecta, instanced three times
03:46 One hop removed, inside the dependency
05:17 Two is the limit
06:37 Already federal policy, not new
07:56 Trusting what you cannot personally check
09:25 The runner nobody re-reads
10:39 Wrap-up
[1] AIShellJack authors. "AIShellJack: A Large-Scale Benchmark for Prompt Injection to Command Execution in AI Coding Assistants." arXiv preprint 2509.22040. September 2025. https://arxiv.org/abs/2509.22040
[2] Guan, A., Liu, Z., Zhong, G. "Comment and Control: Prompt Injection to Credential Theft in Claude Code, Gemini CLI, and GitHub Copilot Agent." oddguan.com. April 2026. https://oddguan.com/blog/comment-and-...
[3] cybersecuritynews.com. Independent trade press coverage of "Comment and Control." 21 April 2026. (No URL captured in the source research package.)
[4] Willison, S. "The Lethal Trifecta." simonwillison.net. 16 June 2025. https://simonwillison.net/2025/Jun/16...
[5] LiteLLM. "Security Update, March 2026." docs.litellm.ai. https://docs.litellm.ai/blog/security...
[6] GitHub. Security Advisory GHSA-5mg7-485q-xm76. https://github.com/advisories/GHSA-5m...
[7] CloudSEK. "AI Supply Chain Breach: 2,500+ Companies, 434,000 CI/CD Pipelines." https://www.cloudsek.com/blog/ai-supp...
[8] Varonis Threat Labs. "CoSnitch." https://www.varonis.com/blog/cosnitch
[9] The Hacker News. "Microsoft Copilot Personal Flaws Could Allow Automatic Prompt Execution." August 2026. https://thehackernews.com/2026/08/mic...
[10] Willison, S. "New Prompt Injection Papers." simonwillison.net. 2 November 2025 (covering Meta AI safety team's "Agents Rule of Two," 31 October 2025). https://simonwillison.net/2025/Nov/2/...
[11] NCSC New Zealand. New Zealand Information Security Manual, v3.9. Released 9 May 2025. (No URL independently re-fetched this session; carried from the research package.)
[12] UK National Cyber Security Centre. Software supply-chain security guidance. May 2026. (No URL independently re-fetched this session; carried from the research package.)
[13] GitHub, Inc. "actions/runner" open-source repository. https://github.com/actions/runner
[14] Cybersecurity and Infrastructure Security Agency; Office of Management and Budget. "Secure Software Development Attestation Form," under Executive Order 14028 and OMB Memorandum M-22-18. Released 11 March 2024. https://www.cisa.gov/resources-tools/...
[15] National Institute of Standards and Technology. "Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities." NIST Special Publication 800-218. February 2022. https://csrc.nist.gov/pubs/sp/800/218...