---
title: "Comment and Control: nội dung PR đánh cắp secret từ agent CI · DotsAgent"
description: "Prompt injection trong nội dung pull request và issue đã đánh cắp secret CI từ Claude Code Security Review, Gemini CLI Action và GitHub Copilot Agent."
url: https://dotsagent.io/vi/security/incidents/2026-04-comment-and-control-ci-secrets
---

15 tháng 4, 2026

# Comment and Control: nội dung PR đánh cắp secret từ agent CI

Prompt injection trong nội dung pull request và issue đã đánh cắp secret CI từ Claude Code Security Review, Gemini CLI Action và GitHub Copilot Agent.

## Chuyện gì đã xảy ra

Ngày 15 April 2026, nhà nghiên cứu Aonan Guan công bố Comment and Control, một loạt tấn công nhắm vào các AI agent chạy trong CI. Văn bản trong pull request hoặc issue chứa chỉ dẫn mà agent làm theo khi có quyền truy cập vào secret của workflow. Claude Code Security Review, Gemini CLI Action và GitHub Copilot Agent đều bị ảnh hưởng.

The Register đưa tin Anthropic, Google và Microsoft đã trả tiền thưởng tìm lỗi cho các phát hiện này. Không có CVE nào được cấp.

## Vì sao cuộc tấn công thành công

Các workflow này đưa văn bản từ bất kỳ ai có thể mở pull request hoặc issue cho agent xem, trong khi agent cũng có quyền truy cập vào secret của repository và có thể đăng hoặc gửi dữ liệu. Đây là bộ ba chí mạng ngay trên CI runner của bạn.

## Cần làm gì

- Không cấp secret cho các job agent mà người ngoài có thể kích hoạt bằng pull request, issue hoặc comment.
- Chỉ cấp cho các job đó token chỉ đọc và không cho truy cập mạng ngoài phạm vi cần thiết để review.
- Coi tiêu đề, mô tả, comment và diff của PR là dữ liệu đầu vào không đáng tin cậy.
- Chỉ chạy các job cần secret sau khi maintainer phê duyệt lần chạy.

[Không để lộ secret trong các lượt chạy CI không đáng tin cậy](https://dotsagent.io/vi/security#ciSecretIsolation)[Dùng thông tin xác thực với quyền tối thiểu](https://dotsagent.io/vi/security#leastPrivilege)[Phá vỡ bộ ba nguy hiểm](https://dotsagent.io/vi/security#lethalTrifecta)

- [Tự động phê duyệt WebFetch trong Claude Code làm rò rỉ dữ liệu qua huggingface.co](https://dotsagent.io/vi/security/incidents/2026-06-claude-code-webfetch-exfiltration)

- [MCP TypeScript SDK làm rò rỉ phản hồi giữa các client](https://dotsagent.io/vi/security/incidents/2026-02-mcp-typescript-sdk-response-leak)

[Làm theo checklist bảo mật →](https://dotsagent.io/vi/security/checklist)

## Nguồn

1. [oddguan.com](https://oddguan.com/blog/comment-and-control-prompt-injection-credential-theft-claude-code-gemini-cli-github-copilot/)/blog/comment-and-control-prompt-injection-credential-theft-claude-cod
2. [theregister.com](https://www.theregister.com/security/2026/04/15/anthropic-google-microsoft-paid-ai-bug-bounties-quietly/5221934)/security/2026/04/15/anthropic-google-microsoft-paid-ai-bug-bounties-q

Tài liệu tham khảo độc lập dành cho những người xây dựng AI agent. Không liên kết với bất kỳ nhà cung cấp nào được nêu ở đây.

© 2026 DotsAgent · Dữ liệu được kiểm tra ngày 1 tháng 10, 2026
