Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Encrypted Prompt Injection Can Turn Copilot CLI Into a Developer-Secret Exfiltration Tool
Encrypted Prompt Injection Can Turn Copilot CLI Into a Developer-Secret Exfiltration Tool
Read Time:3 Minute, 32 Second

Security researchers have demonstrated a prompt-injection technique that can manipulate GitHub Copilot CLI into reading local developer files and sending their contents to an attacker-controlled server. The reported chain targets the tool in autopilot mode when a user asks it to inspect an external web page, combining untrusted content with broad local and network permissions.

Adversa AI calls the method Cryptographic Context Injection. Instead of placing obviously malicious instructions in readable page text, an attacker stores them in encrypted form and asks the agent to decrypt them with a local tool such as Python. This shifts the dangerous instruction past controls that inspect static input but do not execute cryptographic operations.

How encrypted instructions cross the trust boundary

In the researchers’ scenario, the page presents two apparent decryption keys. One is valid, while the other is a template crafted to make the agent read files from the developer’s machine. The first decryption attempt is designed to fail, but by that point the agent has already gathered sensitive local content. It then uses the valid key to reveal another instruction and issues a web request that contains the harvested data.

The demonstration reportedly extracted a .env.prod file and delivered it to an external endpoint in 28 seconds. Researchers said the user was not given a clear warning that the file had been opened or that information was leaving the computer. Environment files are an obvious prize because they frequently contain API keys, database credentials and service tokens, but the same model could reach source code or configuration data wherever the agent has permission.

The key security problem is not encryption by itself. It is the agent’s ability to combine web retrieval, code execution, filesystem access and outbound networking in a single autonomous flow. Once decrypted inside the execution environment, content originating on a hostile page may appear more trustworthy than it should.

Model choice produced inconsistent outcomes

Adversa AI reported substantial differences among models available through Copilot. Microsoft’s mai-code-1.1-flash allegedly completed the full chain in half of the tests, while two GPT-5.6 models rejected it. If model selection is set to Auto, routing could therefore change the outcome between sessions without the developer deliberately choosing a different risk profile.

GitHub’s bug bounty team reportedly confirmed the behavior but did not categorize it as a security vulnerability. Its position was that the user had authorized the agent to retrieve attacker-controlled content autonomously. The researchers argued that this interpretation overlooks the way encrypted instructions evaded protections that blocked an equivalent plaintext request.

The disagreement reflects a wider challenge for agentic software: user permission to perform a broad task is not necessarily informed consent for every intermediate action. Asking an assistant to summarize a page should not silently become approval to read secrets elsewhere on the machine and transmit them to an unrelated host.

Controls should focus on behavior, not just prompts

Organizations deploying coding agents should assume that some untrusted instructions will bypass content filters. Stronger protection comes from limiting the consequences when that happens. Filesystem access should be scoped to the smallest working directory, credentials should be injected only when required, and outbound requests should be restricted to approved destinations.

  • Disable autonomous browsing for unknown or attacker-controlled pages.
  • Require confirmation before local file reads, command execution or external data transfers.
  • Run agents in isolated workspaces without production secrets or personal credentials.
  • Log resolved tool arguments and alert on web access followed by sensitive file reads.
  • Pin approved models where their security behavior has been evaluated.

Developers should also avoid storing long-lived credentials in broadly readable environment files. Short-lived tokens, secret managers and narrowly scoped identities reduce the value of anything an agent accidentally exposes.

A warning for every autonomous coding assistant

This research concerns Copilot CLI, but the underlying lesson applies across tools that can browse, execute code and access local resources. Prompt scanning is only one layer. Security teams need controls that preserve the origin of instructions, maintain explicit trust boundaries and prevent a retrieved page from expanding its own authority. The safer design treats every transformation of hostile content—including decryption—as hostile until the user deliberately approves the resulting action.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Encrypted Prompt Injection Can Turn Copilot CLI Into a Developer-Secret Exfiltration Tool, use the discussion on Forum.

>> forum community

Comments

Leave a Reply