What can Github do about this ?
Why should Github do anything? If you execute arbitrary instructions whether via LLM or otherwise, that's a you problem.
The LLM prompt injection was an entry-point to run the code they needed, but it was still within an untrusted context where the authors had forseen that people would be able to run arbitrary code ("This ensures that even if a malicious user attempts prompt injection via issue content, Claude cannot modify repository code, create branches, or open PRs.")