Microsoft flags secret exposure risk in Claude Code GitHub Action

Microsoft Threat Intelligence said Anthropic’s Claude Code GitHub Action could expose CI/CD secrets when it processes untrusted GitHub content. Anthropic fixed the issue in Claude Code 2.1.128 by blocking access to sensitive /proc files, according to Microsoft.

Microsoft flags secret exposure risk in Claude Code GitHub Action

Microsoft Threat Intelligence says Anthropic’s Claude Code GitHub Action could expose workflow secrets when it processes untrusted content from GitHub issues, pull requests, and comments. The risk, according to Microsoft, came from an access control gap in the agent’s Read tool, which could reach sensitive process files inside the GitHub Actions runner.

The issue matters because GitHub Actions is commonly used for CI/CD, or continuous integration and continuous delivery, which automates tasks such as testing, builds, and deployments. In this setup, a workflow may have access to repository data, environment variables, tokens, cloud credentials, and other secrets needed to do its job.

⚡ New to this?

This is about an AI helper inside GitHub Actions, which is automation used to run tests, handle pull requests, and other CI/CD tasks. Microsoft says a flaw in how the Claude Code GitHub Action handled files could let a malicious issue or comment expose secrets from the runner. Non-experts should care because CI/CD systems often hold keys and tokens that protect code, cloud services, and deployments.

🦞 OpenClaw angle

If you run AI agents in GitHub Actions, split jobs so the agent that reads issues or PRs cannot also touch secrets or external network tools. Put secret access in a separate workflow step or a separate job with tighter permissions, and avoid giving the same agent file-read plus commit or web access. Update any Claude Code deployments to a fixed version and review workflows for /proc access, full environment exposure, and any path where untrusted markdown can influence tool calls.

Microsoft said the problem appeared when Claude Code Action handled attacker-controlled text inside issue bodies, pull request descriptions, or comments. That text could be embedded in a prompt injection attempt, where content that looks like normal issue discussion is actually crafted to steer the AI agent into taking unsafe actions.

The company said it observed prompt injection attempts in public repositories using AI-assisted GitHub workflows across multiple vendors. In one example, Microsoft described payloads hidden inside HTML comments so they would not be visible in a browser, but would still be read by the model because it processes raw markdown.

Microsoft also described a separate attack chain in a documentation workflow that used permissive GitHub Actions settings. In that case, an AI bot was allowed to search the local repo, read files, and create pull requests. Microsoft said the payload disguised itself as a feature request for “diagnostic telemetry” and instructed the bot step by step to find a file, append malicious HTML, and open a pull request.

According to Microsoft, that kind of workflow can be dangerous because an attacker does not need direct write access if the AI agent is allowed to modify files and communicate externally. In the example Microsoft gave, the result was an invisible XSS, or cross-site scripting, payload that could have run in visitors’ browsers if the pull request had been merged.

The specific Claude Code issue involved the Read tool. Microsoft said Anthropic had already added environment scrubbing for subprocess execution paths such as Bash, using Bubblewrap-based sandboxing and a scrubbed environment for some action types. But the Read tool was not isolated in the same way, and Microsoft said it could access /proc/self/environ directly.

That file can include environment variables from the runner, including ANTHROPIC_API_KEY and potentially other credentials. Microsoft said its proof-of-concept prompt caused Claude to read the file and expose the key, even when the workflow’s subprocess environment scrubbing was active.

Microsoft said the attack could also bypass GitHub’s secret scanner. Because the model was instructed to alter the key before outputting it, the leaked value was not presented in the exact form the scanner expects. Microsoft said the attacker could then reconstruct the full API key by adding the omitted prefix.

Anthropic mitigated the issue in Claude Code version 2.1.128, according to Microsoft. The company said the fix blocks access to sensitive files under /proc/. Microsoft reported the issue to Anthropic through HackerOne on April 29, 2026, and Anthropic shipped the mitigation on May 5, 2026.

Microsoft said defenders should treat AI workflows that process untrusted GitHub content as high-risk when they also have access to secrets, file-read tools, or external communication channels. The company framed the broader problem as a trust-boundary failure: once an agent can read untrusted input and act on it inside a CI runner, natural-language text can become an execution path.

Source: Microsoft Security Blog ↗

More from Security News