Security engineer Aonan Guan, working with Johns Hopkins University researchers, disclosed “Comment and Control,” a prompt-injection technique that hijacked three widely used AI coding agents — Anthropic’s Claude Code Security Review, Google’s Gemini CLI Action, and GitHub Copilot Agent — through booby-trapped GitHub pull request titles, issue bodies and comments. Each agent could be manipulated into executing arbitrary commands and publicly posting its own API key or access token, bypassing model-level and platform-level safeguards designed to prevent exactly that. The disclosure, published April 16, 2026, was a coordinated research finding with no reported real-world exploitation; the three vendors paid bug bounties of $100 (Anthropic), $1,337 (Google) and $500 (GitHub).