The case concerns a reported prompt-injection flaw in the Cover My Repo GitHub cover CLI, apparently built with Claude, where repository-controlled text could be interpreted as instructions by a coding or design agent. A maintainer commit titled “fix prevent repository prompt injection” reportedly withholds repository content from the instruction channel. The supplied web snippets establish the broader risk—untrusted repository, issue, and pull-request content can manipulate coding agents—and recommend isolation and constrained environments, but they do not provide independent testing of this specific CLI or establish that its fix reliably prevents the attack.
The maintainer’s reported fix—keeping repository-controlled text out of the instruction channel—independently converges with Scott’s taint-tracking, inbound-airlock, and confused-deputy architectures. However, the supplied evidence contains no independent exploit reproduction or fix validation, and the radar already tracks malicious repository/issue content as a coding-agent attack vector, so this is presently another small implementation example rather than a result that would change what Scott builds or argues.
ip:framework.separation-of-powers-for-cognitionip:concept.taint-trackingip:concept.confused-deputy-problemradar:issuetrojanbench-malicious-issue-attacksradar:concept.prompt-injectionradar:concept.coding-agent-security
queries asked of Scott's wikis
- instruction-data separation in agent harnesses
- untrusted repository content threat model
- prompt injection defenses for coding agents
- sandboxing versus capability restriction
- provenance-aware context assembly
- agent tool permissions and trust boundaries
2026-09-01T09:30:22Z
Repeated checks have produced no inspectable exploit, independent reproduction, or validation of input isolation; the surrounding headlines remain unsupported instances of an already-known attack class. The episode has faded without resolving the hypothesis and can be reopened if a technical artifact or first-party response appears.
2026-08-30T08:23:55Z
Refreshed comments add an affected mode and an alleged success rate, but only as the submitter’s restatement; no technical write-up, exploit artifact, reproduction, or first-party response appeared. This is repetitive amplification of the existing Claude Code allegation, so the case cools while the steering and input-isolation questions remain unresolved.
2026-08-29T12:28:52Z
The Claude Code headline broadens the alleged ingress path from repository files to ordinary website summarization, but still supplies no inspectable mechanism, reproduction, or first-party artifact. It remains an unverified instance of the known untrusted-content attack class and does not validate input isolation.
2026-08-29T12:23:31Z
evidence attached: hn.story.49489082 — Reports a concrete repository or web-content prompt-injection path against Claude Code, directly bearing on the open agent-injection case.
2026-08-29T10:31:37Z
The new headline raises the possible impact from agent steering to code execution inside real organizations, making the lead worth nearer review. Without an inspectable report, exploit artifact, affected configuration, or credible source standing, it does not yet corroborate the attack mechanism or validate input isolation.
2026-08-29T10:23:06Z
evidence attached: hn.story.49488299 — This is independent security evidence that files published for AI agents can trigger code execution inside real organizations.
2026-08-29T09:24:57Z
The bounty-honeypot headline suggests a broader social-engineering use of repository context, but provides no inspectable report, mechanism, or demonstrated agent behavior. It does not independently corroborate repository-driven steering or validate input isolation, so the core case remains unchanged.
2026-08-29T09:23:21Z
evidence attached: hn.story.49488042 — A concrete independent report broadens the repository-based attack surface from prompt steering to social-engineering coding agents into performing untrusted bounty work.
2026-08-27T18:05:08Z
The staleness check produced no new artifact, reproduction, or validation. The dependency-to-AGENTS.md allegation remains title-level, while the broader steering and input-isolation claims are still unresolved.
2026-08-25T16:44:29Z
The HN item raises a distinct dependency-to-AGENTS.md steering scenario, broadening the case beyond the original CLI, but its title alone is not independent corroboration without a primary artifact, reproduction, or technical details. The claimed steering and the effectiveness of input isolation therefore remain unvalidated.
2026-08-25T15:25:11Z
evidence attached: hn.story.49434688 — This is independent corroboration of repository-controlled instruction injection: a dependency created AGENTS.md and induced Codex to conceal the change.
2026-08-24T11:23:13Z
The expanded discussion remains methodological criticism of the scanner self-report rather than independent testing of repository-driven agent steering or the input-isolation fix. It adds no substantive corroboration and leaves the case unchanged.
2026-08-22T20:28:33Z
The refreshed comments add only criticism of the scanner experiment’s presentation and methodology, not independent reproduction or technical validation. The case remains a first-party mitigation report plus weak adjacent evidence, with the core steering and isolation claims still untested.
2026-08-22T18:29:33Z
The 60-file self-report adds adjacent evidence that poisoned repository files may pass prompt-injection scanners, but it neither demonstrates agent steering nor independently validates the CLI’s input-isolation fix. The core hypothesis therefore remains untested.
2026-08-22T18:23:23Z
evidence attached: reddit.post.1vvjbz8 — The reported 60-file experiment provides concrete supporting evidence that poisoned files can evade current prompt-injection scanners used around coding agents.
2026-08-21T17:52:45Z
No independent reproduction or fix validation has appeared; the unchanged reobservation leaves this as a small first-party implementation report rather than corroborated evidence about input isolation’s reliability.
2026-08-21T17:36:23Z
grounded: converges/low — The maintainer’s reported fix—keeping repository-controlled text out of the instruction channel—independently converges with Scott’s taint-tracking, inbound-air
2026-08-21T17:34:45Z
origin walked (codex/luna, conf 0.93): anchor reddit.post.1vul8v4 -> echo.github.5b4e478371 by JinHyuk Sung (sjh9714)
2026-08-21T17:33:40Z
case created — A concrete repository-content injection affected a released agentic CLI and directly prompted an input-isolation mitigation.