logo

AI GitHub Agents: How One Issue Leaked Private Repos | UpGuard

ID: 2ee90947-c87a-5c02-a36a-2d81050ad986

STIX ID: report--2ee90947-c87a-5c02-a36a-2d81050ad986

Feed Name: UpGuard Blog

Threat Score
75/100

Date Published: 2026-05-13

Date Updated: 2026-05-20

...
...

**Executive summary:** This report documents architectural prompt-injection and tool-poisoning vulnerabilities in AI agent ecosystems (MCP servers) demonstrated by researcher-led incidents that exfiltrated private GitHub repositories and Supabase database tokens; it explains attack vectors (indirect prompt injection, tool poisoning, tool chaining), presents case studies and the "lethal trifecta" risk model, and offers rapid assessment guidance for organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.