"[...] adding the keyword “Additionally” triggered unintended behavior in the model, causing it to reframe its output rather than refuse it."
A simple word and the security of your product is jeopardized...
noma.security/blog/gitlost...
noma.security
GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos - Noma Security
TL;DR: Noma Labs discovered a critical prompt injection vulnerability within GitHub’s new Agentic Workflows, allowing an unauthenticated attacker to silently pull data from private repositories by pos...