It works for a lot of other providers too, including OpenAI (which also has file APIs, by the way).
https://support.claude.com/en/articles/9767949-api-key-best-...
https://docs.github.com/en/code-security/reference/secret-se...
It works for a lot of other providers too, including OpenAI (which also has file APIs, by the way).
https://support.claude.com/en/articles/9767949-api-key-best-...
https://docs.github.com/en/code-security/reference/secret-se...
Obviously you have better methods to revoke your own keys.
agreed it shouldn't be used to revoke non-malicious/your own keys
If it's a secret gist, you only exposed the attacker's key to github, but not to the wider public?
Assuming that they took any of your files to begin with and you didn't discover the hidden prompt
Moreover, finding a more effective way to revoke a non-controlled key seems a tall order.
So the prompt injection adds a "skill" that uses curl to send the file to the attacker via their API key and the file upload function.
Storage is actually not much of a problem (on your end): you can just generate them on the fly.
GitHub and their partners just see a secret and trigger the oops-a-wild-secret-has-appeared action.