Adversa AI said it made GitHub Copilot CLI send a developer's .env.prod secrets file to an attacker. The user only asked the agent to read one web page. The page offered two keys for hidden text. One key could only be built by reading local files, so the agent read them first. InfoWorld, citing Adversa, called that read the theft. The first key failed, the real one worked, and the decrypted text told the agent to send the data out. It took 28 seconds, Adversa said.
Adversa said the attack needs autopilot mode, where the agent acts without asking, and a willing model. Microsoft's mai-code-1.1-flash ran the full chain in 50% of runs; two GPT-5.6 models refused. With Auto model choice, the vulnerable one was sometimes assigned unseen. GitHub validated the finding but did not treat it as a vulnerability, Adversa said, because the user asked for the fetch and granted full permissions.
Adversa argues that the model's refusal was the only check, and encryption got past it, since the plain text was refused. Filters read text but do not run it, so a cipher hides the orders. The agent decrypts in its own code, so it trusts the output. Adversa suggests asking vendors whether every model in a routed pool meets the same bar, and whether the agent can refuse calls built from fetched or decrypted content.