Security researchers at Noma Security disclosed “GitLost,” a prompt-injection flaw in GitHub’s Agentic Workflows feature that could let an attacker extract private repository data with no credentials or access of their own. By embedding hidden instructions inside a public GitHub issue, an attacker could trick an organization’s AI agent — which had read access to both public and private repositories — into publishing confidential file contents as a public comment on the issue. The flaw was demonstrated as a proof-of-concept through responsible disclosure; no real-world exploitation was reported.