Source · DiggingBeagle record
ASSET Research Group: We put the exploit in a picture. The AI code reviewer never opened it.
Primary ASSET Research Group disclosure dated June 2026. It documents the failed plaintext precursor, the split AGENTS.md + PNG attack, CodeRabbit/Bugbot review behavior, a 6,480-PR review survey, a fabricated validator/postmortem cover story, end-to-end synthetic .env recovery, ten-session model/harness comparisons, a 49/50 attack and 0/30 benign multimodal-reviewer trial, controlled-test limitations and vendor disclosure.
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
Primary ASSET Research Group disclosure dated June 2026. It documents the failed plaintext precursor, the split AGENTS.md + PNG attack, CodeRabbit/Bugbot review behavior, a 6,480-PR review survey, a fabricated validator/postmortem cover story, end-to-end synthetic .env recovery, ten-session model/harness comparisons, a 49/50 attack and 0/30 benign multimodal-reviewer trial, controlled-test limitations and vendor disclosure.
Claim-level citations (8)
- supportsGhostCommit hid agent instructions in a repository image and exfiltrated synthetic secrets through generated code: ASSET reports surveying 6,480 pull requests across the 300 most active public repositories over the preceding 90 days; in that sample, 73% of merged pull requests reached the default branch without substantive human review and without bot review.
Opening paragraph, survey of 6,480 pull requests across 300 active public repositories
- supportsGhostCommit hid agent instructions in a repository image and exfiltrated synthetic secrets through generated code: The GhostCommit attack splits the malicious instruction across an innocuous repository convention and a PNG: AGENTS.md points the coding agent to the image, while the image contains the instructions to read .env, encode its bytes and emit them into generated source.
Sections 'So we moved the instruction into a picture', lines describing AGENTS.md and build-spec.png
- supportsGhostCommit hid agent instructions in a repository image and exfiltrated synthetic secrets through generated code: In the researchers' tested pull request, CodeRabbit's default configuration excluded PNG files and Cursor Bugbot returned no findings against the image-based payload, even though the image explicitly contained the secret-access instructions.
Section 'So we moved the instruction into a picture', discussion of CodeRabbit PNG exclusion and Bugbot no-findings result
- supportsGhostCommit hid agent instructions in a repository image and exfiltrated synthetic secrets through generated code: The evolved GhostCommit fixture does not rely on the PNG alone: it adds a roughly fifty-line fake provenance validator and a fabricated incident postmortem so the repository convention appears to have an operational purpose and can pass a coherence-oriented review.
Section 'So we moved the instruction into a picture', paragraph describing the fifty-line fake provenance validator and fabricated incident writeup
- supportsGhostCommit hid agent instructions in a repository image and exfiltrated synthetic secrets through generated code: In ASSET's ten-session-per-row disclosure matrix, Cursor leaked the complete synthetic .env with Sonnet 4.6, Composer-2 and GPT-5.5; Antigravity leaked with Sonnet 4.6, Gemini 3.1 Pro and Gemini 3 Flash; Claude Code refused with Sonnet 4.6, Haiku 4.5 and Opus 4.7; and Antigravity/Opus wrote the secret-derived value but removed it before completion. The same Sonnet 4.6 therefore leaked under Cursor and Antigravity but refused under Claude Code.
Section 'It only works if the agent can see', ten-session-per-row coding tool + model matrix
- supportsGhostCommit hid agent instructions in a repository image and exfiltrated synthetic secrets through generated code: ASSET reports that its multimodal pull-request defender, which inspects convention text and images as separate inputs, detected 49 of 50 attacks in a live trial of 80 previously unseen pull requests, including every image-channel variant, while flagging none of the 30 benign pull requests.
Section 'A reviewer that opens the image', live trial against eighty real pull requests
- supportsGhostCommit hid agent instructions in a repository image and exfiltrated synthetic secrets through generated code: GhostCommit is a proof of concept using synthetic credentials in repositories controlled by the researchers; the cited material does not establish production exploitation or theft of real secrets.
Final disclosure note stating results are from controlled tests with seeded non-production credentials and no real secrets
- supportsGhostCommit hid agent instructions in a repository image and exfiltrated synthetic secrets through generated code: In a controlled end-to-end run, Cursor driving Claude Sonnet followed the image-carried instruction during a later ordinary coding task and wrote the seeded synthetic .env into source code as 311 integers that decoded byte-for-byte to the file.
Section 'What the agent does after you merge', end-to-end Cursor/Sonnet run and 311-integer provenance constant
Cite this record
DiggingBeagle. “ASSET Research Group: We put the exploit in a picture. The AI code reviewer never opened it..” https://diggingbeagle.com/sources/asset-research-group-we-put-the-exploit-in-a-picture-the-ai-code-reviewer-never-/
Citation guidance