Back to all lessons
Awareness Lessons
3 months ago

Hidden Image Payloads Exploit AI Code Reviewers to Steal Secrets

The Ghostcommit technique exploits a fundamental blind spot: AI code review agents process text-based files but do not inspect image content, allowing adversaries to embed prompt injection instructions invisibly inside PNG files submitted via pull requests. When downstream coding agents later process these images, they can be manipulated into exfiltrating sensitive secrets (e.g., API keys, credentials) stored in .env files, encoding them to evade standard secret-scanning tools. This attack highlights that AI-assisted development pipelines introduce entirely new trust boundaries that traditional security controls were not designed to cover. As AI agents gain more autonomous capabilities within CI/CD workflows, any unvalidated input — including binary assets — becomes a potential attack vector for supply chain compromise.

Tactical Insight

Immediate actions

  • Restrict AI coding agents from having read access to sensitive files such as `.env`, credential stores, or secret management configs by default.
  • Audit all current AI code reviewer integrations (e.g., CodeRabbit, Bugbot) to understand what file types and repository scopes they can access.
  • Enforce mandatory human review of any pull request containing binary assets (images, PDFs, archives) before merging.

Long-term improvements

  • Implement least-privilege access controls for all AI agents, scoping repository permissions to only the files and branches strictly necessary for their function.
  • Store secrets exclusively in dedicated secret management solutions (e.g., HashiCorp Vault, AWS Secrets Manager) and never in `.env` files committed to or accessible within the repository.
  • Establish a vetting and approval process for third-party AI tools integrated into CI/CD pipelines, treating them as supply chain risks.

Detection measures

  • Deploy network egress monitoring on CI/CD pipeline environments to alert on unexpected outbound data transfers from build or review agents.
  • Extend secret scanning rules to detect encoded or obfuscated representations of secrets (e.g., numeric-encoded strings, base64 variants) in pipeline outputs and logs.
  • Implement behavioral anomaly detection on AI agent activity to flag deviations such as unexpected file reads or external API calls during code review tasks.