•SiTech AI Team
Cryptographic Context Injection Attack Leaks Developer Secrets via GitHub Copilot CLI
A single web page can make GitHub Copilot CLI read local files, including .env.prod secrets, and send them to an attacker in 28 seconds. The attack hides instructions as ciphertext the agent decrypts itself.