BREAKING
'Ghostcommit' Hides Attacks in Images
How The Attack Works
1
Add AGENTS.md + image
↓
2
Hidden PNG instruction
↓
3
Reviewers skip images
↓
4
Agent leaks .env
0
PRs analyzed
0
%
merged unreviewed
0
top repos
Same Model, Opposite Behavior
Cursor + Sonnet 4.6
Leaked
●
Leaked full .env
●
311 integer tuples
●
On the first try
Claude Code
Refused
●
Sonnet, Haiku, Opus
●
Refused in all cases
●
Blocked the attack
0
attacks caught
0
false positives
0
benign PRs
Open And Analyze Every Image
AI NEWS BLITZ
A new proof-of-concept called Ghostcommit hides prompt injection inside images to fool AI code reviewers.