TL;DR: Unosecur finds GitHub Copilot CLI can be driven to read developer secrets from local files and exfiltrate them through encrypted prompt injection when autopilot mode and permissive access are enabled. The core issue is not the payload alone but standing agent access that makes secret theft a governance problem, not just a prompt-safety problem.
Editorial analysis by NHI Mgmt Group, based on content published by Unosecur: “GitHub Copilot CLI Vulnerability Lets Attackers Steal Developer Secrets via Encrypted Prompt Injection”.
Key questions
A: The control that breaks is session scoping.
Q: Why do permissive agent settings increase the risk of secret theft?
A: They expand the agent's effective privilege envelope beyond what most teams intend.
Q: How can security teams tell whether an agent is becoming a secret-exfiltration risk?
A: Watch for the combination of local file reads, context growth from sensitive paths, and outbound requests in the same session.
Practitioner guidance
- Audit agent sessions for standing file access Identify every use of Copilot CLI or similar tools that can read working-directory files such as .env, then remove sensitive material from those paths and scope access to the task.
- Eliminate broad autopilot and allow-all settings Find shell aliases, wrapper scripts, and settings that enable autopilot, allow-all-tools, or allow-all-urls, then disable them for any environment that handles secrets.
- Separate secret access from browsing Run web-browsing agents in a sandbox or container that has no production credentials mounted, and pull secrets at runtime only from a controlled vault path.
Bottom line: The article shows that a developer agent with file access and outbound network access can be turned into a secret-exfiltration path without a traditional exploit.
What's in the full article
Unosecur's full analysis covers the operational detail this post intentionally leaves for the source:
- The exact Copilot CLI settings and session conditions that made the encrypted prompt injection chain possible
- The model-selection behaviour behind Auto mode and why some sessions reproduced the issue while others did not
- The step-by-step sequence of file reads, decryption, and outbound exfiltration that demonstrates the attack path
- The vendor-specific governance features proposed for discovering and scoping agent access across cloud and SaaS environments
👉 Read Unosecur's analysis of the GitHub Copilot CLI secret-theft chain →
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Autopilot access is not a convenience feature when an agent can read secrets and exfiltrate them. The governance assumption behind developer tooling is that the operator can notice and contain risky actions before sensitive material leaves the session. That assumption breaks when the agent can select, combine, and execute steps fast enough to turn local file access into outbound loss within one workflow. Practitioners should treat agent runtime behaviour as a permission boundary, not just a productivity setting.
A few things that frame the scale:
- Developers using GenAI tools like GitHub Copilot are reporting 35% productivity gains, according to IDC’s 2024 Generative AI Study.
A question worth separating out:
Q: How should organisations govern developer agents that browse the web?
A: Treat them as non-human identities with explicit reach limits, not as ordinary developer tools. The right model is task-scoped access, no standing secrets in the workspace, constrained egress, and session-level logging. The moment a browsing agent can also see production credentials, governance has failed before the first request is sent.
👉 Read our full editorial: GitHub Copilot CLI exposes the identity problem in agentic access