August 16, 2026

Three AI coding agents leaked secrets through a single prompt injection. One vendor's system card predicted it

white and brown city buildings during daytime
Unsplash

A security researcher, working with colleagues at Johns Hopkins University, opened a GitHub pull request, typed a malicious instruction into the PR title, and watched Anthropic’s Claude Code Security Review action post its own API key as a comment. T...