Trust & Security
GitLost: One Word Bypasses GitHub’s Agentic Workflows, Exposing the Same Trust Flaw as Agentjacking
Noma Labs discloses a prompt injection vulnerability in GitHub's Agentic Workflows that allows unauthenticated exfiltration of private repository data. The guardrail bypass – a single keyword – reveals the same MCP trust architecture failure behind Agentjacking.
◆ Heath Callahan