← Back to stories
AI

Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets

GitHub Copilot CLI may reveal developer secrets if it comes across instructions that tell it to do so, depending on the underlying model. The coding agent tool was flagged earlier this year for being susceptible to indirect prompt injection. That's when a model ingests text from a source other than the user that directs it to take some action outside the scope of its intended function. This is more of the same, with a twist. According to security researchers at Adversa AI, GitHub Copilot CLI suffers from the same vulnerability identified in Grok two months ago: Cryptographic Context Injection (CCI). Imagine a GitHub Copilot CLI user is working on a project and running the agent in autopilot mode. In other agentic coding tools like Anthropic's Claude, that's the default, but it remains optional for GitHub Copilot CLI. …

You're reading a preview. The full article is published by The Register on their website.

Read the full story on The Register