dotsagent.io
语言:简体中文

评论与控制:PR 文本窃取 CI Agent 的机密

pull request 和 issue 文本中的提示注入窃取了 Claude Code Security Review、Gemini CLI Action 和 GitHub Copilot Agent 的 CI 机密。

事件经过

2026 年 4 月 15 日,研究人员 Aonan Guan 发布了 Comment and Control,介绍了一组针对在 CI 中运行的 AI Agent 的攻击。攻击者在 pull request 或 issue 中加入指令,Agent 在能够访问 workflow 机密时照做了。Claude Code Security Review、Gemini CLI Action 和 GitHub Copilot Agent 均受到影响。

The Register 报道称,Anthropic、Google 和 Microsoft 为这些发现支付了漏洞赏金。没有发布 CVE。

攻击奏效的原因

这些 workflow 会把任何有权创建 pull request 或 issue 的人提交的文本交给 Agent,而该 Agent 同时还能访问 repository 机密并发布或发送数据。这就是在 CI runner 上出现的致命三要素。

应对措施

  • 不要向外部人员可通过 pull request、issue 或评论触发的 Agent 任务提供机密。
  • 为这些任务提供只读 token,并限制其网络访问范围,只允许审核所需的访问。
  • 将 PR 标题、描述、评论和 diff 都视为不可信输入。
  • 仅在维护者批准运行后,才运行需要机密的任务。

不要在不可信的 CI 运行中暴露密钥使用最小权限凭据拆解致命三要素

查看安全检查清单 →

来源

  1. oddguan.com/blog/comment-and-control-prompt-injection-credential-theft-claude-cod
  2. theregister.com/security/2026/04/15/anthropic-google-microsoft-paid-ai-bug-bounties-q

为 AI agent 开发者提供的独立参考资料。与此处提及的任何厂商均无关联。

© 2026 DotsAgent · 事实核查日期:2026年10月1日