Preliminary research
Poisoning Claude Code: One GitHub Issue to Break the Supply Chain
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
Claude Code's GitHub Action treated any actor ending in [bot] as having write access, and agent mode never checked the actor was human, so an attacker's own GitHub App, able to open issues on any public repo, feeds it untrusted text. A prompt injection disguised as a read error makes Claude read /proc/self/environ and post it back with mcp__github__update_issue, exposing the OIDC request token, which exchanges for the Claude App installation token and pushes to the action's own repo.
Record
- Researcher
- RyotaK
- Published by
- GMO Flatt Security Research
- Date
- Topic
- Supply
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of RyotaK, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .