Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

GhostCommit demonstrates a gap between what a code reviewer inspects and what a later coding agent can interpret: a pull request can contain an image whose rendered text gives an agent instructions that text-focused review misses. In the controlled proof of concept, an agent later read a test .env file and encoded its contents as integers in source code. Researchers reported that the tested image-based pull requests passed CodeRabbit and Cursor Bugbot review; this was not a confirmed production compromise and does not establish how every configuration behaves.

How the GhostCommit attack worked

The demonstration split its instructions between two repository artifacts. An AGENTS.md convention file told the coding agent to derive a value from a referenced image. The PNG displayed the consequential instruction: read .env and encode its bytes as integers in source code. The image did not need to execute anything. It only needed to be interpreted by an agent that had access to files in the repository.

This created an inspection and authority mismatch. A reviewer or human concentrating on the text diff might see an ordinary convention-file change and treat the PNG as opaque. A later multimodal coding agent could read the image as project guidance. Once merged, the instruction could remain dormant until a developer asked an agent to perform routine work. The Cloud Security Alliance account and BleepingComputer’s report describe this delayed chain.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why the disclosure could look like ordinary code

In the reported demonstration, Cursor using Claude Sonnet emitted a 311-integer constant that decoded byte for byte to the test .env file. The disclosure path was a source-code change containing numeric data, not an outbound network request. A scanner that primarily looks for recognizable credential strings may not identify a secret represented as integers unless it also detects or decodes suspicious numeric sequences.

What the review tests found—and what they do not prove

The researchers reported that CodeRabbit’s default configuration excluded images and that Cursor Bugbot returned no findings on their image-based pull requests. They also reported that Bugbot flagged a plaintext variant. These are results from the tested scenario, not evidence that either product always misses image-based instructions.

The Cloud Security Alliance note also reports that tested Cursor and Antigravity configurations followed the injected instruction with several models, while Claude Code refused across the tested models. It describes a partial exception in which Claude Opus under Antigravity wrote the secret and then removed it. These bounded observations are not a universal product ranking or a guarantee about current versions, settings, or behavior.

Lineaje characterizes the demonstration as a controlled proof of concept using synthetic credentials in isolated repositories—not a confirmed attack on a production victim. Lineaje’s account provides that qualification. The available reporting does not establish that real-world credentials were stolen through this attack.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How can an image bypass AI code review?

An image can carry instructions in rendered text while remaining a binary asset to a review process that does not inspect image contents. If a later coding agent can interpret that text and treats repository conventions or referenced files as trusted guidance, the image becomes a way to influence the agent across a trust boundary. The risk is not limited to malicious code in a diff: the image can influence what the agent does when it is given a later task.

The potential impact depends on the agent’s permissions. If it can read secrets such as .env, an instruction embedded in an image may persuade it to move those contents into a location that appears less sensitive, such as a source file. Integer encoding can make that change less recognizable to scanners designed for conventional keys, passwords, or tokens.

What the reported numbers mean

The Cloud Security Alliance note attributes two notable results to ASSET Research Group’s 2026 work. They describe particular samples and researcher tests, not general rates or independent certifications.

Reported result What was measured How to interpret it
73% of merged changes reached the default branch without substantive human or bot review ASSET Research Group’s sample of 6,480 pull requests across 300 active public repositories over 90 days, as described by the Cloud Security Alliance A result for that sample, not a universal industry-wide rate. Source
79 of 80 previously unseen attack pull requests blocked; zero false positives across 30 legitimate pull requests The researchers’ prototype image-aware reviewer, as reported by the Cloud Security Alliance and BleepingComputer A result from the researchers’ test set, not independent product certification or a guarantee of future performance. Cloud Security Alliance; BleepingComputer
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How development teams can reduce the risk

No single review feature eliminates the underlying problem. Controls should address what agents can read, which repository content they treat as instructions, and what changes can reach the codebase.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Inspect referenced images and repository instructions

  • Review images linked from AGENTS.md, CLAUDE.md, and similar convention files, especially when a change adds or modifies an instruction that directs an agent to an asset.
  • Use image-aware review where available, or add a separate review step that checks referenced image content instead of assuming a binary asset is inert.
  • Assess repository guidance as untrusted input: a convention file should not by itself authorize an agent to access secrets or perform sensitive actions.

Limit agent access to secrets

  • Remove standing access to .env files and equivalent secret stores from routine coding-agent sessions when that access is unnecessary.
  • Require separate authorization or human review before an agent reads sensitive files or makes changes that could expose their contents.
  • Keep permissions narrow enough that following an untrusted repository instruction cannot automatically disclose credentials.

Extend checks beyond credential-shaped strings

  • Look for suspicious numeric tuples or other encoded data in code changes, particularly when a change is unexpectedly large or appears unrelated to the task.
  • Consider whether scanning can identify encoded content that decodes to secrets; conventional pattern matching may not recognize integer-encoded bytes.
  • Retain review gates for unusual source changes even when automated secret scanning reports no findings.

The Cloud Security Alliance’s recommendations focus on auditing referenced images, adding image-aware review, extending secret scanning to encoded data, and reducing agents’ access to secrets. These measures work in layers; they are not a promise of complete protection. Read the CSA recommendations.

What to check when evaluating an AI review or coding workflow

A useful assessment is about the entire workflow, not just the name of a review tool. Check whether image contents are inspected, how repository instructions and referenced assets are handled, what secrets the coding agent can access, and which independent approval gates apply before sensitive reads or code changes. The reported tests do not support a broad vendor ranking.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.