Comment and Control: PR text steals secrets from CI agents
Prompt injection in pull request and issue text stole CI secrets from Claude Code Security Review, Gemini CLI Action and GitHub Copilot Agent.
What happened
On 15 April 2026 researcher Aonan Guan published Comment and Control, a set of attacks on AI agents that run in CI. Text placed in a pull request or issue carried instructions that the agent followed while it had access to the workflow's secrets. Claude Code Security Review, Gemini CLI Action and GitHub Copilot Agent were all affected.
The Register reported that Anthropic, Google and Microsoft paid bug bounties for the findings. No CVEs were issued.
Why it worked
These workflows put text from anyone who can open a pull request or issue in front of an agent that also holds repository secrets and can post or send data. That is the lethal trifecta running on your CI runner.
What to do
- Don't pass secrets to agent jobs that outsiders can trigger with a pull request, issue or comment.
- Give those jobs a read-only token and no network access beyond what the review needs.
- Treat PR titles, descriptions, comments and diffs as hostile input.
- Run jobs that need secrets only after a maintainer approves the run.
Keep secrets out of untrusted CI runsUse least-privilege credentialsBreak the lethal trifecta
Claude Code WebFetch auto-approval let data out via huggingface.co
MCP TypeScript SDK leaked responses between clients
Work through the security checklist →