{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/invariant-github-mcp-toxic-agent-flow-2025/",
 "asOf": "2026-09-26",
 "id": "invariant-github-mcp-toxic-agent-flow-2025",
 "date": "2025-05-26",
 "datePrecision": "day",
 "title": "Invariant Labs shows GitHub MCP agents can be steered by a public issue to leak private repo data",
 "lane": "attack",
 "kind": "vulnerability-disclosure",
 "summary": "Invariant Labs demonstrated that a malicious issue in a public repository could lead an agent using the GitHub MCP server to read the user's private repositories and publish the data in a public pull request. The firm tested with Claude 4 Opus and argues there is no server-side patch because the flaw lies in agent permissions, recommending per-session repository scoping and runtime monitoring.",
 "whyItMatters": "It is a canonical 'toxic agent flow' where legitimate tools and a broad token combine into a data leak.",
 "actors": [
  "invariant-labs",
  "github"
 ],
 "topics": [
  "tool-and-mcp-security",
  "prompt-injection",
  "data-exfiltration"
 ],
 "atlas": [
  "untrusted-content",
  "tools",
  "credentials"
 ],
 "artifacts": [
  "mcp-scan"
 ],
 "sources": [
  {
   "url": "https://invariantlabs.ai/blog/mcp-github-vulnerability",
   "publisher": "Invariant Labs",
   "title": "GitHub MCP Exploited: Accessing private repositories via MCP",
   "date": "2025-05-26",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "The attack was demonstrated with Claude 4 Opus.",
   "locator": "Main write-up"
  },
  {
   "fact": "Invariant states the issue is architectural and cannot be fixed by a GitHub server-side patch alone.",
   "locator": "Mitigations"
  }
 ],
 "significance": 4,
 "fideQuestions": [],
 "methods": [
  "agent-data-exfiltration",
  "tool-poisoning"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}