2026-10-11 17:11 UTC

Independent testing will determine whether untrusted repository text can reliably steer sandboxed coding and design agents and whether isolating such content from instructions prevents the attack.

state: expiredheat: lowuncertainty: highconvergesscott: lowagentic-security prompt-injection input-isolationCover My RepoClaudeCodexCursor

What is this?

The case concerns a reported prompt-injection flaw in the Cover My Repo GitHub cover CLI, apparently built with Claude, where repository-controlled text could be interpreted as instructions by a coding or design agent. A maintainer commit titled “fix prevent repository prompt injection” reportedly withholds repository content from the instruction channel. The supplied web snippets establish the broader risk—untrusted repository, issue, and pull-request content can manipulate coding agents—and recommend isolation and constrained environments, but they do not provide independent testing of this specific CLI or establish that its fix reliably prevents the attack.

Why it matters to Scott

The maintainer’s reported fix—keeping repository-controlled text out of the instruction channel—independently converges with Scott’s taint-tracking, inbound-airlock, and confused-deputy architectures. However, the supplied evidence contains no independent exploit reproduction or fix validation, and the radar already tracks malicious repository/issue content as a coding-agent attack vector, so this is presently another small implementation example rather than a result that would change what Scott builds or argues.
ip:framework.separation-of-powers-for-cognitionip:concept.taint-trackingip:concept.confused-deputy-problemradar:issuetrojanbench-malicious-issue-attacksradar:concept.prompt-injectionradar:concept.coding-agent-security
queries asked of Scott's wikis
  • instruction-data separation in agent harnesses
  • untrusted repository content threat model
  • prompt injection defenses for coding agents
  • sandboxing versus capability restriction
  • provenance-aware context assembly
  • agent tool permissions and trust boundaries

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (7) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟠 redditA Reddit comment found a prompt injection hole in the GitHub cover CLI I built with Claude
ClaudeAI
Due_Emu_822901
🟧 echo.github ⭐The earliest primary artifact is the maintainer's security-fix commit, titled “fix prevent repository prompt injection.” It says: “Withhold JinHyuk Sung (sjh9714)——
🟠 redditLook at me: I am the frontier Lab now - PromptInjectBench: asked Huihui-Qwen3.6-35B to write 60 prompt injection attacks on files used or generated by Hermes. Shieldstral scanned each of them->It caught zero/nothing/nada. All 60 poisoned prompts passed the scanning. GPT-OSS_safeG caught 10%
LocalLLaMA
JLeonsarmiento012
🟧 hnA Go dependency wrote AGENTS.md mid-build and got Codex to hide the changewakahiu30
🟧 hnSome GitHub bounty repos are honeypots that farm free work from AI agentsninetyquid10
🟧 hnWe Ran Code Inside Fortune 500s Using Files They Published for AI Agentsnizbit31
🟧 hnClaude Code can be tricked simply by asking it to summarize a websitechrisjj46

Interpretation history

Decision trace