Attack  ·  Glossary

Repository-Borne Prompt Injection

An attack where malicious instructions are hidden in a code repository (file names, comments, code snippets) so that when an AI coding agent clones and analyzes the repository, it automatically reads the injected instructions and acts on them without human awareness.
Developers regularly open untrusted code repositories in their editors and AI coding agents analyze them automatically. A malicious repository becomes an invisible supply-chain weapon that silently hijacks the agent.
Track this in the live feed See how this plays out in real AI security and governance developments.
Open the feed →