Chors.net
Blog & Insights

Precyzyjna wiedza
o ciemnych systemach.

Ekspercka analiza i studia przypadków dla decydentów. Nawigacja po złożonościach nowoczesnej infrastruktury cyfrowej z niekompromisowymi standardami bezpieczeństwa.

Can Your AI Agent Leak Company Secrets Without You Knowing?

Lead

More companies are letting AI agents (Copilot, Claude Code) autonomously review code, pull requests, and documentation — without realizing that a single hidden instruction in a PR description can turn that agent into a data exfiltration tool. See how CHORS.NET's Audyt Podatności (Vulnerability Audit) catches this class of risk before an attacker does.

What actually happened: the Azure DevOps MCP flaw

Francisco Rosales of Manifold Security disclosed on July 21, 2026, a "confused deputy" vulnerability in Microsoft's official Model Context Protocol (MCP) server for Azure DevOps. An attacker with contributor access to a single project can embed invisible instructions inside a pull request description — hidden in an HTML comment, invisible in the UI, but fully readable by the API and the AI agent.

When a victim — typically a senior developer with broader access — asks their AI agent to review the PR, the hidden instructions hijack its behavior. In a proof of concept validated against both Copilot CLI and Claude Code, the compromised agent ran a pipeline in a different project, read a confidential wiki page the attacker could not access, and posted its contents back as a comment on the attacker's own PR.

Why this isn't just a developer problem

This case shows that AI agent security is no longer confined to IT departments — it affects any business running LLM-based automation. The flaw stems from inconsistent application of a defense mechanism called "spotlighting" across MCP tools, leaving a gap that can be exploited without detection.

The confused deputy mechanism in practice

The attack relies on what researcher Simon Willison calls the "lethal trifecta": access to private data, exposure to untrusted content, and the ability to exfiltrate information. When all three elements combine in one agent workflow, the risk of hijacking grows regardless of how well the underlying code itself is secured.

Microsoft's response and the lack of a systemic fix

Microsoft acknowledged the issue after Manifold Security reported it through the Microsoft Security Response Center, recognizing it as a known class of AI risk, but as of disclosure it had not shipped a fix or assigned a CVE. Microsoft recommends limiting project access scopes and manually reviewing changes before letting AI tools act — which in practice shifts the burden of detection onto individual organizations.

The broader pattern: agentic workflows as a new attack surface

A similar architectural flaw was described in May 2025 by researchers at Invariant Labs in GitHub's MCP server, where malicious content in issues could leak code from private repositories. Rosales warns that the risk grows as organizations automate agent workflows: PR reviews, triage, and summaries triggered automatically without human prompting mean an injected PR description doesn't wait to be asked — it becomes an entry point that fires on its own.

"In that world the injected PR description isn't waiting for someone to ask — it's an entry point that fires on its own."

— Francisco Rosales, Manifold Security

Expert perspective from CHORS.NET

As Marcin Białczyk, AI systems operator and founder of CHORS.NET, notes from his own experience deploying agents like Hermes and Agent Zero:

"Every new agent connected to company systems is a new exposure point that needs to be tested, not assumed safe just because the vendor shipped it."

Engineer Marcin Białczyk, Founder and Cybersecurity Operator, CHORS.NET

How to check if your company is exposed

  1. Identify every place where AI agents (Copilot, Claude Code, custom MCP servers) can access content generated by external users, such as PR descriptions, issues, or comments.
  2. Verify whether your tool vendor applies spotlighting-type defenses consistently across all endpoints, not just selected ones.
  3. Restrict agent access scope following least-privilege principles — one project, one permission set.
  4. Confirm that automated triggers (PR reviews, triage) log agent actions in a way that allows anomaly detection.
  5. Order a Vulnerability Audit that specifically assesses exposure related to AI integrations and automation.

Frequently asked questions

Does this vulnerability only affect Azure DevOps?

No. The confused deputy and lethal trifecta patterns are architectural, already found in GitHub's MCP server, and can apply to any tool connecting AI agents to untrusted external content.

Is my company exposed if we don't use Azure DevOps?

If you use any AI agents connected to code management, wiki, or ticketing systems (via MCP, Copilot, Claude Code, etc.), the risk applies regardless of vendor — what matters is how permissions and content filtering are configured.

How does CHORS.NET help assess this type of risk?

CHORS.NET's Audyt Podatności analyzes integration configurations, including exposure points related to automation and AI, and delivers a business-language report with concrete remediation recommendations within 3-7 days.

Is a one-time audit enough, or do I need continuous monitoring?

Since AI tools and their integrations evolve quickly, a one-time Vulnerability Audit is a good starting point, but companies actively relying on AI agents in production workflows should consider Continuous Monitoring for ongoing verification.

Check your company's exposure now

Don't wait for a hidden instruction in a PR or issue to turn your AI agent against you. Order a CHORS.NET Vulnerability Audit and find out exactly where your business is exposed.

Sources

  1. Manifold Security — Azure DevOps MCP server vulnerability
  2. Simon Willison — The lethal trifecta for AI agents
  3. Invariant Labs — GitHub MCP vulnerability
  4. Docker — MCP horror stories: GitHub prompt injection
  5. CHORS.NET — Audyt Podatności (Vulnerability Audit)

CHORS Cryptogram

Minimalistyczny zapis na miesięczne analizy. Surowe dane, trendy audytowe i analiza zero-day prosto na skrzynkę. Zero marketingowego szumu.

Klucz GPG dostępny na życzenie.