---
title: "GitHub MCP 恶意 agent 流程泄露私有仓库数据 · DotsAgent"
description: "Invariant Labs 展示了攻击者如何利用恶意的公开 GitHub issue 引导 GitHub MCP server 上的 agent，将私有仓库数据复制到公开 pull request 中。"
url: https://dotsagent.io/zh/security/incidents/2025-05-github-mcp-toxic-agent-flow
---

2025年5月26日

# GitHub MCP 恶意 agent 流程通过公开 issue 泄露私有仓库数据

Invariant Labs 展示了攻击者如何利用恶意的公开 GitHub issue 引导 GitHub MCP server 上的 agent，将私有仓库数据复制到公开 pull request 中。

## 事件经过

2025 年 5 月 26 日，Invariant Labs 披露了一起涉及 GitHub MCP server 的攻击事件，并将其称为“有毒 agent 流程”。攻击者在公开仓库中创建一个 issue，并在其中写入针对 agent 的指令。之后，agent 读取未关闭的 issue 时，会接触到攻击者植入的文本并照其执行。

Agent 使用的 token 还可能有权访问仓库所有者的私有仓库。Agent 按照 issue 中的指令，从这些私有仓库中提取数据，并通过公开仓库中的 pull request 发布，任何人都能读取这些数据。

## 攻击奏效的原因

致命三要素在同一个会话中全部出现：能够访问私有仓库的 token、来自公开 issue 的不可信文本，以及作为数据出口的公开 pull request。每一项单独看都很常见，但三者组合后，任何能创建 issue 的人都可以读取该 token 有权访问的所有内容。

## 应对措施

- 让 agent 读取公开 issue 时，为其提供仅限该仓库的 token。
- 将公开仓库和私有仓库分别放在不同的 agent 会话中。
- 要求在 agent 于公开仓库中创建 pull request、发表评论或提交 commit 前先获得批准。
- 将 issue 标题、正文和评论视为不可信输入。

[拆解致命三要素](https://dotsagent.io/zh/security#lethalTrifecta)[使用最小权限凭据](https://dotsagent.io/zh/security#leastPrivilege)[重大操作须经人工批准](https://dotsagent.io/zh/security#humanApproval)

- [EchoLeak：Microsoft 365 Copilot 遭遇零点击数据窃取](https://dotsagent.io/zh/security/incidents/2025-06-echoleak-m365-copilot)

- [MCP 工具投毒：工具描述中的隐藏指令](https://dotsagent.io/zh/security/incidents/2025-04-mcp-tool-poisoning)

[查看安全检查清单 →](https://dotsagent.io/zh/security/checklist)

## 来源

1. [invariantlabs.ai](https://invariantlabs.ai/blog/mcp-github-vulnerability)/blog/mcp-github-vulnerability

为 AI agent 开发者提供的独立参考资料。与此处提及的任何厂商均无关联。

© 2026 DotsAgent · 事实核查日期：2026年10月1日
