Agents hooked into GitHub can steal creds – but Anthropic, Google, and Microsoft haven't warned users
Claude, Gemini, and Copilot agents can steal GitHub credentials. The vendors knew. Users didn't.

Why it matters
A critical security vulnerability in AI agent integrations exposes enterprise credentials at scale, raising questions about vendor transparency and the safety governance of agentic AI deployments in production workflows.
The key facts
5 to knowGitHub-integrated AI agents from Anthropic (Claude), Google (Gemini), and Microsoft (Copilot) vulnerable to credential theft
Security flaw allows malicious prompts or compromised repos to extract stored authentication tokens
Major vendors aware of vulnerability but have not issued public security warnings or user advisories
Affects production deployments across enterprises relying on these agents for code workflows
Raises governance questions around safety disclosure and responsible AI deployment practices
Go to the source
The Register AI/MLgo.theregister.com
