Hidden Image Instructions Hack Code Agents

sunychoudhary · reddit · 2026-07-13

Researchers designed an attack called Ghostcommit: hiding malicious instructions inside PNG images, making them invisible to AI code reviewers. The workflow: During the review phase, the AI reviewer doesn't open images, so it approves the PR. Later, when the code agent reads the image, it is instructed to open the repo's `.env` file and write the secrets back into the source code disguised as numbers, leading to a leak. This demonstrates that: - Visual files can serve as prompt injection vectors - Relying solely on an initial AI review is unreliable - Structured permission controls and human oversight are still required for sensitive operations

Related event: Ghostcommit Attack Hides Prompts in PNGs to Bypass AI Code Review(2 posts)→

Original post →

More from coding & agent

coding & agent channel →