{
  "id": 6374663,
  "title": "I attacked my own repo — my PR bot blocked the attack itself",
  "url": "https://urgent.news/2026/09/09/ich-habe-mein-eigenes-repo-angegriffen-mein-pr-bot-hat-den-angriff",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-09T03:03:26.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/agentguard/ich-habe-mein-eigenes-repo-angegriffen-mein-pr-bot-hat-den-angriff-selbst-blockiert-3cfo"
  },
  "original_language": "de",
  "account": "A developer has created a tool called AgentGuard to protect against coding agents that read and execute instructions from a repository. The tool was tested with 12 targeted attacks, all of which were detected without false positives. A scan of 30 public repositories, including those of Google, Microsoft, and Nextcloud, revealed 5 with critical findings. The developer also demonstrated the tool's effectiveness by having it block their own pull request and by seeing it block a live attack on a GitHub repository. AgentGuard is available on the GitHub Marketplace with a MIT license, offering a free initial scan for public repositories.",
  "summary": "Coding-agenten, such als Claude Code, Cursor und Codex, lesen Repositories und folgen ihnen. Der Autor von AgentGuard baute ein CI-Gate für Agent-Konfigurationen, um zu testen, was passiert, wenn jemand eine Anweisung ins Repository schmuggelt, die der Agent ausführen kann. Nachdem er 12 gezielte Angriffe ins eigenes Repository eingebracht hatte, stellte der AgentGuard alle 12 Angriffe korrekt fest, ohne dass falsch positive Ergebnisse auftauchten.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}