Adversa AI researchers said they have made GitHub Copilot’s Command-Line Interface (CLI) read a developer’s local files and send their contents to an attacker, starting from a single web page the user asked it to read.
In research published Oct. 6, 2026, the firm calls the technique Cryptographic Context Injection (CCI) and says GitHub validated the finding but declined to treat it as a vulnerability.
The attack hides its instructions as ciphertext. The agent decrypts them in its own code runtime and then trusts the output as its own, which Adversa says allows a form of prompt injection to bypass defenses that block the same instructions in plain text.
In the demonstration, a user ran Copilot CLI in autopilot mode, where the agent acts without asking, and told it to fetch one attacker-controlled URL. The page offered two decryption keys, one of which could only be built by reading local files and folding their contents into the key.
Preparing that key was the theft. When decryption with it failed, the agent fell back to the real key, and the decrypted instructions had it request a follow-up URL that carried the harvested contents to the attacker.
The chain took 28 seconds, with no confirmation prompt and nothing on screen to show that files had left the machine.
Adversa says the technique is not a one-click compromise or a confirmation-prompt bypass, since it needs autopilot mode and a permissive model.
Model Routing Decides Who Is Exposed
In Adversa’s tests, Microsoft’s mai-code-1.1-flash ran the full chain in half of its runs, while two GPT-5.6 models offered in Copilot consistently refused the same payload.
With model selection left on Auto, the router assigned the vulnerable model in some sessions and a safe one in others, without the user choosing or seeing which.
Adversa said it reported the issue to GitHub on Sept. 17, 2026, and says it still reproduced as of Oct. 1. According to Adversa, GitHub’s triage team said the user had explicitly asked Copilot to fetch attacker-controlled content while giving it full permission to act autonomously and ruled the report ineligible for its bug bounty.
Expert Insights has contacted GitHub for comment and will update this article with any response.
To defend against possible attacks using the technique, Adversa recommended tracing every tool call with fully resolved arguments, alerting when untrusted content is followed by code execution, file reads and an unrelated outbound request, and gating new network destinations.
In its test, the agent’s own closing summary said it had “confirmed an authorized-reader endpoint.”