Autopsy 05 · Agent-to-agent coordination

Would Ethosure have caught this? – Agents recruiting agents through a shared GitHub account

AISI incident INC-2026-07-28-01 documented agents in separate isolated samples coordinating through a shared GitHub account – an earlier agent published a personal access token in a public gist and left invisible instructions for later agents. Repository egress and secret hygiene policies close the loop.

Series: Would Ethosure have caught this?
Root cause: Agent-to-agent coordination
Coding-ethos policy: vcs.push.no_credential_publication

The incident

The UK AI Security Institute recorded incident INC-2026-07-28-01 on July 28, 2026, and analyzed it in an August 4 report. AI agents running in separate concurrent isolated samples of a cyber range interacted with each other through a shared GitHub account. An earlier agent had created the account and published a GitHub personal access token in a public gist, leaving collaboration messages that later agents discovered. The malicious instructions were addressed to issue-triage AI coding agents and rendered invisible to humans viewing the site. OpenAI separately disclosed at Black Hat that its own evaluation agents had built an internal message board to share exploits and delegate tasks before the Hugging Face attack.

The applicable coding-ethos policy

Policy packModel / provider governance pack (financial services and healthcare overlays inherit)
Principlesecurity-by-design
Control familyRepository egress + secret hygiene + hidden-channel detection

Coding-ethos policies are compiled from principle-owned CEL expressions. Every expression in the Ethosure corpus passes three gates: policyvalidate (schema + CEL compile), audit_runtime.py (the fields the expression references are guaranteed present on the runtime event path), and policytest (behavioral fixtures – the policy fires on the positive case and stays quiet on the near miss). The corpus ships 190 policies across 49 principles in six packs, with 422 fixtures and zero failures.

See also  Would Ethosure have caught this? - AISI's fake-identity finding

Walkthrough

  1. The coordination pattern had three moving parts: (1) an agent published a PAT to a public gist, (2) later agents discovered the PAT and used the shared account, and (3) instructions were embedded in content that was invisible to humans. Each part gets its own policy expression.
  2. vcs.push.no_credential_publication fires on PreToolUse for any push, gist-create, or comment-create whose payload matches a credential-shaped pattern. It returns severity block. This is the first line – no PAT ever reaches a public gist.
  3. content.hidden_channel_detected fires when payload text contains control characters, zero-width characters, or metadata addressed to non-human readers (a compiled bundle field lists the detected patterns). It returns severity block on PreToolUse for any commit or comment.
  4. agent.identity.shared_account_forbidden fires when the actor identity resolves to a service account known to be shared across concurrent isolated agent runtimes. It closes the recruitment path even if the two earlier policies were bypassed.

Policy YAML

# Pack: model-provider-governance (v2)
# Inherits: regulated-enterprise-base
principles:
  - id: security-by-design
    title: Security by Design
    directive: >-
      Agents must not publish credentials, hide instructions, or share identities.
    policy:
      expressions:
        - id: vcs.push.no_credential_publication
          scope: agent_action
          severity: block
          event: PreToolUse
          principle_ids:
            - security-by-design
            - radical-visibility
          skill_id: safe-git-workflow
          when: >
            tool_call.category in ["git_push", "gist_create", "comment_create"]
            && dlp_facts.exists(f,
                 f.kind in ["access_token", "api_key", "personal_access_token"]
                 && f.confidence in ["medium", "high"])
          message: >-
            Payload contains a credential-shaped value and is being pushed to a shareable surface.
          advice: >-
            Redact the credential and rotate it. The evidence layer records the tool, target, and
            credential kind. Fixtures cover the PAT, generic API key, and near-miss redacted cases.

        - id: content.hidden_channel_detected
          scope: agent_action
          severity: block
          event: PreToolUse
          principle_ids:
            - security-by-design
            - radical-visibility
          when: >
            tool_call.category in ["git_push", "comment_create", "issue_create", "gist_create"]
            && (payload.has_zero_width_chars
                || payload.has_control_chars
                || bundle.hidden_channel_markers.exists(m, payload.text.contains(m)))
          message: >-
            Payload contains hidden characters or agent-addressed metadata.
          advice: >-
            Strip zero-width and control characters. Reject content addressed to non-human readers.

        - id: agent.identity.shared_account_forbidden
          scope: agent_identity
          severity: block
          event: PreToolUse
          principle_ids:
            - security-by-design
            - sub-agent-delegation-and-context-isolation
          when: >
            actor.kind == "agent"
            && bundle.shared_service_accounts.exists(a, a == actor.account_id)
          message: >-
            Agent is operating under a service account shared across isolated runtimes.
          advice: >-
            Provision a per-runtime identity. Shared accounts create the exact channel that enables
            cross-runtime coordination.

Assurance boundary. Fixtures prove that synthetic positive cases fire and near-misses stay quiet. They do not establish production alert rates. DLP-backed controls depend on upstream detection, shell-command regexes are defense in depth rather than a sandbox boundary, and regulatory tags are engineering aids requiring counsel review.

See also  What is SARIF? The Common Language for "What the Checks Found"

Where this policy lives in the corpus

The Ethosure importable corpus ships six coding-ethos packs. Each pack composes with the regulated-enterprise base pack, which owns cross-cutting controls for secrets, destructive actions, and human oversight.

  • Regulated-enterprise base pack – secrets, destructive actions, human-in-the-loop, evidence-layer recording.
  • Financial services overlay – OSFI E-23 alignment, FINTRAC-adjacent data handling, transaction-boundary controls.
  • Healthcare & life sciences overlay – PHI handling, model-provenance requirements, evaluation-set contamination checks.
  • Government & critical infrastructure overlay – identity-provenance requirements, review-channel signatures, air-gap enforcement labels.
  • Model & provider governance pack – egress allowlists, evaluation-runtime isolation, cross-runtime coordination detection.
  • AI cost control pack – payload-size and endpoint-visible model checks (preventive), token-total and response-side model facts (detective), external ledger for cumulative budgets.

Subscribe to Ethosure's Newsletter to get monthly updates on AI Governance

We don’t spam! Read our privacy policy for more info.