🤖 GitHub Copilot CLI prompt chain can exfiltrate local secrets
Adversa AI disclosed a Cryptographic Context Injection technique against GitHub Copilot CLI in autopilot mode. In the demonstrated chain, an attacker-controlled webpage fed encrypted instructions, pushed the agent to read local files while building a fake decryption key, then triggered a second request that sent the collected data off-host. Researchers reported a .env.prod file was exfiltrated in 28 seconds.
The key issue is trust at runtime: plaintext revealed after decryption was treated as valid context even when equivalent visible instructions were refused. GitHub reportedly validated the behavior but did not classify it as a vulnerability.
🛰️ Open sources - closed narratives
@sitreports
Post #39536
198
