Invariant Labs demonstrated that a malicious issue in a public repository could lead an agent using the GitHub MCP server to read the user's private repositories and publish the data in a public pull request. The firm tested with Claude 4 Opus and argues there is no server-side patch because the flaw lies in agent permissions, recommending per-session repository scoping and runtime monitoring.
Why it matters
It is a canonical 'toxic agent flow' where legitimate tools and a broad token combine into a data leak.
Key facts
As stated in the sources, with where to find them.
- The attack was demonstrated with Claude 4 Opus.Main write-up
- Invariant states the issue is architectural and cannot be fixed by a GitHub server-side patch alone.Mitigations
Findings that cite this record
Key questions this bears on
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
Sources
Related records
Apr 1, 2025
Jul 8, 2025
Aug 6, 2025
Jun 10, 2025
Oct 8, 2025
Jun 16, 2025