This is not a failure of agentic AI
It's a failure of basic engineering practices.
Bugs like this could happen (and have happened) in many systems which allow users to search over both public and private data.
It can be *SOLVED* quite simply by ensuring that the AI model used on behalf of those outside the organization does not have access to private repos