Booby-trapped web pages could trick GitHub Copilot CLI into leaking developer secrets
Security researchers at Adversa AI say GitHub Copilot CLI, a coding agent tool, may reveal developer secrets if it reads a web page containing hidden instructions, depending on the underlying model. The technique is called Cryptographic Context Injection (CCI), the same weakness the researchers identified in Grok two months earlier. It builds on indirect prompt injection, where a model ingests text from a source other than the user and is steered into actions outside its intended purpose.
The attack requires the user to run the agent in autopilot mode, which is optional in Copilot CLI but the default in some other agentic coding tools, such as Anthropic's Claude. The user then asks the tool to fetch a malicious page. That page holds encrypted instructions, a direction to decrypt them using Python, and two possible keys. The first key is a decoy that prompts the agent to read targeted files, such as a .env file, and add the contents to the key. Decryption fails. The second key works, and the revealed instructions tell the agent to fetch another URL, which carries the harvested secrets to the attacker.
The researchers argue that static guardrails read text but do not run it. Because the malicious content is strongly encrypted, classifiers that scan ingested text can miss it, unlike simpler encodings such as base64 that models learned to decode in training.