Security firm Adversa hid encrypted instructions in a normal web page; the command line version of GitHub's Copilot ran them and shipped a developer's secret keeping file to an attacker in 28 seconds. The fix is a design problem, not detection.
A poisoned web page can talk GitHub Copilot CLI into reading a developer's local files and shipping them to an attacker in 28 seconds. No malware on the developer side, no confirmation prompt bypass, and nothing on screen that a file ever left the machine.
That is the picture Adversa AI published this week from its Cryptographic Context Injection (CCI) work, the same attack class that hit xAI's Grok chat in August, now pointed at an agent that can touch the filesystem. The Register covered the Copilot CLI disclosure on October 6. The fix is not a mystery; it is a design problem the agent era has to solve the way email eventually solved phishing.
The mental model is the one defenders used to draw for phishing. The open web is the new email inbox: a flood of content an agent will fetch and act on, and a non-trivial slice of that content is hostile by design. The interesting move here is what the attacker does with the envelope. The CCI payload is not text a guardrail can read. It is a strong ciphertext blob plus the key and a polite instruction to decrypt, which the agent does inside its own code-execution runtime. No content classifier executes a cipher at inspection time, and unlike base64 the model cannot take a shortcut in its weights, so the plaintext only exists after the agent has already run it. As Adversa's primary write-up puts it: "Static guardrails read text; they do not run it."
What that buys the attacker on Copilot CLI is a chain with no obvious seam. The user runs the CLI in autopilot mode, the ordinary "go read this page" flow, and pastes in a link. The page presents itself as encrypted content with two candidate keys. One is real; the other is a template the agent has to build, and to build it, it has to read the targeted files off disk and fold their contents into the key string. That read is the theft. The decryption with the bogus key then fails by design, the agent falls back to the real key, and the decrypted second stage tells it to fetch a follow-up URL "for more context" that carries the harvested file contents in its query string. Cyberpress's write-up and a mechanism explainer on dev.to walk through the same chain. Adversa's full chain ran in 28 seconds in their lab, with the agent's own closing summary reporting that it had "confirmed an authorized-reader endpoint."
Two details from the writeup should outlive any patch. First, the success rate depends on which model handles the session, and the user does not get to pick. Microsoft's own mai-code-1.1-flash ran the full chain in 50% of Adversa's attempts. Two OpenAI GPT-5.6 models offered in the same product refused the identical payload. On a paid account the vulnerable model was not the default and had to be selected by hand; on an account with model selection left on Auto, the router assigned the vulnerable model on some sessions and a safe one on others, with no user action away from defaults. The user is handed a less-aligned model silently, mid-workflow, and never told.
Second, the vendor response sets up the policy question. Adversa reported the issue to GitHub's bug bounty program on September 17; GitHub's triage team validated the finding but declined to treat it as a product vulnerability. A GitHub spokesperson told The Register the chain requires a user to intentionally direct Copilot CLI to fetch attacker-controlled or untrusted content and confirm they want to trigger the action. As of October 1, 2026, the chain still reproduces on the affected model, and Adversa is disclosing publicly so defenders can build detections while withholding concrete payloads to avoid exploitation. That response is the design question: every team shipping an agent that fetches the open web will have to answer it on their own.
Three defaults would do most of the work. First, fetched web content should be treated as untrusted input by default, and the agent's trust model should match the browser's, where a page the user did not write is data, not a colleague. Second, the secrets should be scoped. The agent does not need the contents of every file in the working directory, and it does not need to assemble decryption key material from local state; a sandbox that names which files the agent can read would have broken the Copilot CLI chain at the second step. Third, keep a human in the loop on the actions that matter. Outbound HTTP requests to hosts the user has not whitelisted, reads of files outside the working directory, and shell invocations that touch the network are exactly the surface a confirmation gate should sit in front of.
The Copilot CLI disclosure is the second high-profile CCI hit in two months, and the third if you count the Gemini demonstration. Each one will look like a vendor bug report until the design layer catches up, and then they will look like the cheap lessons the agent era paid to learn out loud. The email ecosystem eventually built anti-phishing the same way: not by teaching users to parse every sender, but by treating untrusted content as a layer the rest of the system is responsible for handling. The agent stack needs the same move, and the Adversa chain is the next round of pressure pointing at exactly that work.