AI Agents Vulnerable to Prompt Injection Attacks Hidden in GitHub READMEs
A developer discovered a prompt injection attack embedded in a GitHub repository's README file during a research session with Claude Code, where plain text mimicked a legitimate system message by falsely claiming the date had changed. Rather than using obvious jailbreak phrases, the attacker exploited how AI agents process fetched web content, causing the agent to re-evaluate information based on a fabricated timestamp. A March 2026 study by ReadSecBench tested 500 open-source README files and found that direct embedded commands successfully manipulated AI models roughly 84% of the time, with instructions buried in linked files like CONTRIBUTING.md succeeding at around 91%. Human reviewers fared little better, with the majority of 15 testers failing to detect any problem in flagged documents. Security researchers note that legitimate system instructions are never delivered inside fetched page content, making any system-style markup found within a web page a reliable indicator of a forged or malicious command.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in