security
Jun 5, 2026
By Teun
Microsoft flags secret exposure risk in Claude Code GitHub Action
Microsoft Threat Intelligence said Anthropic’s Claude Code GitHub Action could expose CI/CD secrets when it processes untrusted GitHub content. Anthropic fixed the issue in Claude Code 2.1.128 by blocking access to sensitive /proc files, according to Microsoft.
Microsoft Threat Intelligence says Anthropic’s Claude Code GitHub Action could expose workflow secrets when it processes untrusted content from GitHub issues, pull requests, and comments. The risk, according to Microsoft, came from an access control gap in the agent’s Read tool, which could reach sensitive process files inside the GitHub Actions runner.
The issue matters because GitHub Actions is commonly used for CI/CD, or continuous integration and continuous delivery, which automates tasks such as testing, builds, and deployments. In this setup, a workflow may have access to repository data, environment variables, tokens, cloud credentials, and other secrets needed to do its job.
Microsoft said the problem appeared when Claude Code Action handled attacker-controlled text inside issue bodies, pull request descriptions, or comments. That text could be embedded in a prompt injection attempt, where content that looks like normal issue discussion is actually crafted to steer the AI agent into taking unsafe actions.
The company said it observed prompt injection attempts in public repositories using AI-assisted GitHub workflows across multiple vendors. In one example, Microsoft described payloads hidden inside HTML comments so they would not be visible in a browser, but would still be read by the model because it processes raw markdown.
Microsoft also described a separate attack chain in a documentation workflow that used permissive GitHub Actions settings. In that case, an AI bot was allowed to search the local repo, read files, and create pull requests. Microsoft said the payload disguised itself as a feature request for “diagnostic telemetry” and instructed the bot step by step to find a file, append malicious HTML, and open a pull request.
According to Microsoft, that kind of workflow can be dangerous because an attacker does not need direct write access if the AI agent is allowed to modify files and communicate externally. In the example Microsoft gave, the result was an invisible XSS, or cross-site scripting, payload that could have run in visitors’ browsers if the pull request had been merged.
The specific Claude Code issue involved the Read tool. Microsoft said Anthropic had already added environment scrubbing for subprocess execution paths such as Bash, using Bubblewrap-based sandboxing and a scrubbed environment for some action types. But the Read tool was not isolated in the same way, and Microsoft said it could access /proc/self/environ directly.
That file can include environment variables from the runner, including ANTHROPIC_API_KEY and potentially other credentials. Microsoft said its proof-of-concept prompt caused Claude to read the file and expose the key, even when the workflow’s subprocess environment scrubbing was active.
Microsoft said the attack could also bypass GitHub’s secret scanner. Because the model was instructed to alter the key before outputting it, the leaked value was not presented in the exact form the scanner expects. Microsoft said the attacker could then reconstruct the full API key by adding the omitted prefix.
Anthropic mitigated the issue in Claude Code version 2.1.128, according to Microsoft. The company said the fix blocks access to sensitive files under /proc/. Microsoft reported the issue to Anthropic through HackerOne on April 29, 2026, and Anthropic shipped the mitigation on May 5, 2026.
Microsoft said defenders should treat AI workflows that process untrusted GitHub content as high-risk when they also have access to secrets, file-read tools, or external communication channels. The company framed the broader problem as a trust-boundary failure: once an agent can read untrusted input and act on it inside a CI runner, natural-language text can become an execution path.