'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
ID: 76d91ad7-915b-5994-8008-b0555a6d4250
STIX ID: report--76d91ad7-915b-5994-8008-b0555a6d4250
Feed Name: Bleeping Computer
Researchers from the ASSET Research Group demonstrated a proof-of-concept called 'Ghostcommit' where malicious instructions embedded as readable text inside a PNG referenced by an AGENTS.md file bypass human and bot review; coding agents that follow the convention later read the image, open a repository's .env, encode its bytes as integer constants, and insert them into commits, enabling secret exfiltration. The report highlights a structural blind spot in PR review tooling (many PRs merge with little review), shows tests across multiple agent/tool combinations, and proposes defenses including a multimodal pull-request app that inspects images and runtime monitoring of agent behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
