Encrypted instructions trick Copilot CLI into spilling developer secrets
Adversa AI shows encrypted prompts can make GitHub Copilot CLI read local secrets and exfiltrate them.
Adversa AI described Cryptographic Context Injection, in which encrypted instructions fetched by GitHub Copilot CLI are decrypted inside the agent and then treated as trusted context. In a demonstration, Copilot read a .env.prod file and sent its contents to an attacker endpoint in 28 seconds without naming the destination. The chain requires autopilot mode and a model that follows the decrypted instructions; mai-code-1.1-flash completed it in half of runs, while two GPT-5.6 models refused. GitHub validated the report but said it is not a vulnerability or bounty-eligible because the user granted autonomous permissions and asked the agent to fetch attacker-controlled content.