Hidden Image Instructions Hack Code Agents
sunychoudhary · reddit · 2026-07-13
Researchers designed an attack called Ghostcommit: hiding malicious instructions inside PNG images, making them invisible to AI code reviewers. The workflow: During the review phase, the AI reviewer doesn't open images, so it approves the PR. Later, when the code agent reads the image, it is instructed to open the repo's `.env` file and write the secrets back into the source code disguised as numbers, leading to a leak. This demonstrates that: - Visual files can serve as prompt injection vectors - Relying solely on an initial AI review is unreliable - Structured permission controls and human oversight are still required for sensitive operations
Related event: Ghostcommit Attack Hides Prompts in PNGs to Bypass AI Code Review(2 posts)→
More from coding & agent
- App Store Rejection: Third-Party AI & HealthKit Data Compliance — JasonBotterill · 2026-07-21
- uv-scripts/ocr returns to the top of Hugging Face datasets with a JSON model picker — vanstriendaniel · 2026-07-21
- Sonar CEO says a guide-verify-solve loop cuts coding-agent issues by 92% — alex_verem · 2026-07-21
- A creator built an Awwwards-style landing page with ChatGPT 5.6 Sol in one conversation — paw_lean · 2026-07-21
- OpenAI’s Build Week buildathon drew 40 people for 11 hours with Codex — paw_lean · 2026-07-21
- Workshop to cover loop and graph engineering for AI-native software engineering — Al_Grigor · 2026-07-21