Three AI coding agents leaked secrets through a single prompt injection. One vendor's system card predicted it
Recently, a security researcher and their team at Johns Hopkins University discovered a vulnerability in GitHub Actions, specifically affecting Anthropic’s Claude Code Security Review, Google’s Gemini CLI Action, and GitHub’s Copilot Agent (Microsoft). By injecting a malicious prompt into a …










