Hidden Image Instructions Hack Code Agents
sunychoudhary · reddit · 2026-07-13
Researchers designed an attack called Ghostcommit: hiding malicious instructions inside PNG images, making them invisible to AI code reviewers.
The workflow: During the review phase, the AI reviewer doesn't open images, so it approves the PR. Later, when the code agent reads the image, it is instructed to open the repo's .env file and write the secrets back into the source code disguised as numbers, leading to a leak.
This demonstrates that:
- Visual files can serve as prompt injection vectors
- Relying solely on an initial AI review is unreliable
- Structured permission controls and human oversight are still required for sensitive operations
Related event: Ghostcommit Attack Hides Prompts in PNGs to Bypass AI Code Review(2 posts)→
More from coding & agent
- Alex Townsend posts 200 open problems in numerical linear algebra for humans and AI agents — IgorCarron · 2026-09-11
- Kimi K2.8 Preview rolls out: near-K3 coding performance, 1M context for all tiers — teortaxesTex · 2026-09-11
- Looking for a classifier of software engineering task shapes to pick models per task — StewartalsopIII · 2026-09-11
- Steal this idea: prompt-to-hardware where agents assemble custom devices — paraschopra · 2026-09-11
- Model Is the Least Interesting Part: A Guide to Six Core AI Architectures from RAG to Multi-Agent — goyalshaliniuk · 2026-09-11
- Non-coder builds layered memory architecture: 20k tokens tracks a year of agent conversations — matteoianni · 2026-09-11