---
title: "Comment and Control: ข้อความใน PR ขโมย secret จาก CI agent · DotsAgent"
description: "การโจมตีแบบ prompt injection ในข้อความของ pull request และ issue ขโมย secret จาก Claude Code Security Review, Gemini CLI Action และ GitHub Copilot Agent"
url: https://dotsagent.io/th/security/incidents/2026-04-comment-and-control-ci-secrets
---

15 เมษายน 2569

# Comment and Control: ข้อความใน PR ขโมย secret จาก CI agent

การโจมตีแบบ prompt injection ในข้อความของ pull request และ issue ขโมย secret จาก Claude Code Security Review, Gemini CLI Action และ GitHub Copilot Agent

## เกิดอะไรขึ้น

เมื่อ 15 April 2026 นักวิจัย Aonan Guan เผยแพร่ Comment and Control ซึ่งเป็นชุดการโจมตี AI agent ที่ทำงานใน CI ข้อความใน pull request หรือ issue มีคำสั่งที่ agent ทำตาม ขณะที่ agent เข้าถึง secret ของ workflow ได้ Claude Code Security Review, Gemini CLI Action และ GitHub Copilot Agent ล้วนได้รับผลกระทบ

The Register รายงานว่า Anthropic, Google และ Microsoft จ่ายเงินรางวัลจากโครงการ bug bounty สำหรับการค้นพบเหล่านี้ ไม่มีการออก CVE

## เหตุใดจึงโจมตีสำเร็จ

workflow เหล่านี้นำข้อความจากใครก็ตามที่เปิด pull request หรือ issue ได้มาให้ agent อ่าน ขณะที่ agent มีทั้ง secret ของ repository และความสามารถในการโพสต์หรือส่งข้อมูล นี่คือสามปัจจัยอันตรายร้ายแรงที่มารวมกันบน CI runner ของคุณ

## สิ่งที่ควรทำ

- อย่าส่ง secret ให้ agent job ที่บุคคลภายนอกสั่งให้ทำงานได้ผ่าน pull request, issue หรือ comment
- ให้ job เหล่านั้นใช้ token แบบอ่านอย่างเดียว และจำกัดการเข้าถึงเครือข่ายให้เหลือเท่าที่จำเป็นสำหรับการ review
- ถือว่าชื่อเรื่อง คำอธิบาย comment และ diff ของ PR เป็นอินพุตที่ไม่น่าเชื่อถือ
- เรียกใช้ job ที่ต้องใช้ secret หลังจาก maintainer อนุมัติการทำงานแล้วเท่านั้น

[เก็บ secrets ให้ห่างจาก CI run ที่ไม่น่าเชื่อถือ](https://dotsagent.io/th/security#ciSecretIsolation)[ใช้ข้อมูลรับรองสิทธิ์ขั้นต่ำ](https://dotsagent.io/th/security#leastPrivilege)[ตัดวงจรสามปัจจัยอันตราย](https://dotsagent.io/th/security#lethalTrifecta)

- [การอนุมัติ WebFetch อัตโนมัติใน Claude Code เปิดทางให้ส่งข้อมูลออกผ่าน huggingface.co](https://dotsagent.io/th/security/incidents/2026-06-claude-code-webfetch-exfiltration)

- [MCP TypeScript SDK ส่ง response ข้าม client](https://dotsagent.io/th/security/incidents/2026-02-mcp-typescript-sdk-response-leak)

[ทำตามรายการตรวจสอบความปลอดภัย →](https://dotsagent.io/th/security/checklist)

## แหล่งที่มา

1. [oddguan.com](https://oddguan.com/blog/comment-and-control-prompt-injection-credential-theft-claude-code-gemini-cli-github-copilot/)/blog/comment-and-control-prompt-injection-credential-theft-claude-cod
2. [theregister.com](https://www.theregister.com/security/2026/04/15/anthropic-google-microsoft-paid-ai-bug-bounties-quietly/5221934)/security/2026/04/15/anthropic-google-microsoft-paid-ai-bug-bounties-q

แหล่งอ้างอิงอิสระสำหรับผู้สร้าง AI agent ไม่มีส่วนเกี่ยวข้องกับผู้ให้บริการที่กล่าวถึง

© 2026 DotsAgent · ตรวจสอบข้อมูลเมื่อ 1 ตุลาคม 2569
