Encrypted instructions on a web page can make Copilot CLI in autopilot leak your local secrets
Adversa AI says a page with ciphertext the agent decrypts in its own shell got Copilot CLI in autopilot to read files like .env.prod and send them to an attacker in 28 seconds, working on Microsoft's mai-code-1.1-flash in half its runs while two GPT-5.6 models refused, and Auto routing can hand you the weak model without telling you. GitHub validated the report but says it isn't a vulnerability because the user asked for the fetch, so don't point an autopilot agent at untrusted pages from a directory that holds secrets.
