IncidentsA public GitHub issue coaxed an agent into leaking private code
Invariant Labs called it a toxic agent flow: untrusted input in one repository, privileged access to another, and no barrier between them.
28 May 2025
Invariant Labs demonstrated that a malicious issue in a public repository could steer an agent connected to the GitHub MCP server into reading a private repository and publishing its contents in a pull request.
Occurred 26 May 2025 · Disclosed 26 May 2025 · Record updated 13 September 2026
Private code and personal details could be exposed by any user who let an agent triage public issues with a broadly scoped token. GitHub and Invariant recommended fine-grained tokens and runtime guardrails.
IncidentsInvariant Labs called it a toxic agent flow: untrusted input in one repository, privileged access to another, and no barrier between them.
28 May 2025