---
title: "评论与控制：PR 文本窃取 CI Agent 的机密 · DotsAgent"
description: "pull request 和 issue 文本中的提示注入窃取了 Claude Code Security Review、Gemini CLI Action 和 GitHub Copilot Agent 的 CI 机密。"
url: https://dotsagent.io/zh/security/incidents/2026-04-comment-and-control-ci-secrets
---

2026年4月15日

# 评论与控制：PR 文本窃取 CI Agent 的机密

pull request 和 issue 文本中的提示注入窃取了 Claude Code Security Review、Gemini CLI Action 和 GitHub Copilot Agent 的 CI 机密。

## 事件经过

2026 年 4 月 15 日，研究人员 Aonan Guan 发布了 Comment and Control，介绍了一组针对在 CI 中运行的 AI Agent 的攻击。攻击者在 pull request 或 issue 中加入指令，Agent 在能够访问 workflow 机密时照做了。Claude Code Security Review、Gemini CLI Action 和 GitHub Copilot Agent 均受到影响。

The Register 报道称，Anthropic、Google 和 Microsoft 为这些发现支付了漏洞赏金。没有发布 CVE。

## 攻击奏效的原因

这些 workflow 会把任何有权创建 pull request 或 issue 的人提交的文本交给 Agent，而该 Agent 同时还能访问 repository 机密并发布或发送数据。这就是在 CI runner 上出现的致命三要素。

## 应对措施

- 不要向外部人员可通过 pull request、issue 或评论触发的 Agent 任务提供机密。
- 为这些任务提供只读 token，并限制其网络访问范围，只允许审核所需的访问。
- 将 PR 标题、描述、评论和 diff 都视为不可信输入。
- 仅在维护者批准运行后，才运行需要机密的任务。

[不要在不可信的 CI 运行中暴露密钥](https://dotsagent.io/zh/security#ciSecretIsolation)[使用最小权限凭据](https://dotsagent.io/zh/security#leastPrivilege)[拆解致命三要素](https://dotsagent.io/zh/security#lethalTrifecta)

- [Claude Code 的 WebFetch 自动批准功能可通过 huggingface.co 外传数据](https://dotsagent.io/zh/security/incidents/2026-06-claude-code-webfetch-exfiltration)

- [MCP TypeScript SDK 在客户端之间泄露响应](https://dotsagent.io/zh/security/incidents/2026-02-mcp-typescript-sdk-response-leak)

[查看安全检查清单 →](https://dotsagent.io/zh/security/checklist)

## 来源

1. [oddguan.com](https://oddguan.com/blog/comment-and-control-prompt-injection-credential-theft-claude-code-gemini-cli-github-copilot/)/blog/comment-and-control-prompt-injection-credential-theft-claude-cod
2. [theregister.com](https://www.theregister.com/security/2026/04/15/anthropic-google-microsoft-paid-ai-bug-bounties-quietly/5221934)/security/2026/04/15/anthropic-google-microsoft-paid-ai-bug-bounties-q

为 AI agent 开发者提供的独立参考资料。与此处提及的任何厂商均无关联。

© 2026 DotsAgent · 事实核查日期：2026年10月1日
