[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fCjUhT7qDZU--Z5PVkQeGb5C1-ErvYHCuCpkzCFhjpKE":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"dec8f876-3fda-4fa3-ac36-9c5f45b73020","ai-code-agents-vulnerable-to-prompt-injection-through-github-comments","3d8af685-74d7-470b-97ec-5fc67ebc6acf","AI Code Agents Vulnerable to Prompt Injection Through GitHub Comments","The 'Comment and Control' attack exploited a fundamental architectural flaw where AI code agents from Anthropic, Google, and GitHub processed untrusted input (GitHub comments, PR titles, and issue bodies) in the same runtime environment that had access to powerful tools and sensitive credentials. This allowed attackers to execute arbitrary commands and extract API keys without user interaction in most cases. The vulnerability demonstrates the critical importance of implementing proper input validation and privilege separation when deploying AI agents with elevated access to development environments and secrets.","**Immediate actions:**\n- Audit all AI code agents and disable or restrict access to sensitive credentials and powerful tools\n- Implement input sanitization and validation for all user-generated content processed by AI agents\n- Review and revoke unnecessary permissions granted to AI agents in development environments\n\n**Access control improvements:**\n- Implement principle of least privilege for AI agents, limiting access to only required resources\n- Separate AI agent processing environments from credential storage and high-privilege operations\n- Establish runtime isolation between untrusted input processing and sensitive system access\n\n**Configuration management:**\n- Configure AI agents to operate in sandboxed environments with restricted command execution capabilities\n- Implement security guardrails that cannot be bypassed through prompt manipulation\n- Establish secure coding practices for AI agent integration that treat all external input as potentially malicious",[12,13,14,15,16,17],"CIS Control 3","CIS Control 4","NIST AC-2","NIST AC-3","NIST AC-6","NIST SC-39","published","2026-04-16T14:09:34.470374+00:00","2026-04-16T14:09:34.24+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fwww.securityweek.com\u002Fclaude-code-gemini-cli-github-copilot-agents-vulnerable-to-prompt-injection-via-comments\u002F","claude-code-gemini-cli-github-copilot-agents-vulnerable-to-prompt-injection-via--ea68ea","Claude Code, Gemini CLI, GitHub Copilot Agents Vulnerable to Prompt Injection via Comments",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":33,"name":34,"slug":35,"description":36,"color":37},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]