Your AI Coding Assistant Will Betray You. All Someone Has to Do Is Ask Nicely.
GitHub’s AI agent was tricked into leaking private repositories through simple, polite prompts β no exploit, no zero-day, just a convincing request. The real vulnerability isn’t prompt injection or weak sandboxing. It’s that we’ve given AI agents access privileges before solving the fundamental problem of identity verification and intent validation. Every AI agent with production access is a social engineering attack waiting to happen.