A reported flaw in GitHub’s AI-driven workflow layer shows how prompt-style attacks can turn developer automation into a data-leak risk, even when the account model itself is still intact.
A prompt-injection finding dubbed GitLost points to a familiar collaboration channel becoming a security boundary: a public issue, an agentic workflow, and private repository data at risk.