---
title: "GitHub MCP toxic agent flow leaks private repo data · DotsAgent"
description: "Invariant Labs showed a malicious public GitHub issue steering an agent on the GitHub MCP server into copying private-repo data into a public pull request."
url: https://dotsagent.io/security/incidents/2025-05-github-mcp-toxic-agent-flow
---

May 26, 2025

# GitHub MCP toxic agent flow leaks private repos via a public issue

Invariant Labs showed a malicious public GitHub issue steering an agent on the GitHub MCP server into copying private-repo data into a public pull request.

## What happened

On 26 May 2025 Invariant Labs disclosed what it called a toxic agent flow involving the GitHub MCP server. An attacker opens an issue in a public repository and fills it with instructions aimed at the agent. When the agent later reads the open issues, it takes in the planted text and follows it.

The agent's token could also reach the owner's private repositories. Following the issue's instructions, the agent pulled data from those private repositories and published it in a pull request on the public repository, where anyone could read it.

## Why it worked

All three legs of the lethal trifecta were in one session: a token with access to private repositories, untrusted text from a public issue, and a public pull request as the way out. Each piece is ordinary on its own. Together they let anyone who can open an issue read whatever the token can read.

## What to do

- Give agents that read public issues a token scoped to that single repository.
- Keep public and private repositories in separate agent sessions.
- Require approval before the agent opens pull requests, comments or commits on public repositories.
- Treat issue titles, bodies and comments as untrusted input.

[Break the lethal trifecta](https://dotsagent.io/security#lethalTrifecta)[Use least-privilege credentials](https://dotsagent.io/security#leastPrivilege)[Require approval for consequential actions](https://dotsagent.io/security#humanApproval)

- [EchoLeak: zero-click data theft from Microsoft 365 Copilot](https://dotsagent.io/security/incidents/2025-06-echoleak-m365-copilot)

- [MCP tool poisoning: hidden instructions in tool descriptions](https://dotsagent.io/security/incidents/2025-04-mcp-tool-poisoning)

[Work through the security checklist →](https://dotsagent.io/security/checklist)

## Sources

1. [invariantlabs.ai](https://invariantlabs.ai/blog/mcp-github-vulnerability)/blog/mcp-github-vulnerability

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026
