Researchers have shown that web pages with carefully hidden text, dubbed "zombie instructions," could trick GitHub Copilot CLI into exposing secrets. The technique takes advantage of how the tool processes content while assisting developers, especially when it is run in autopilot mode.
The CLI interprets what it reads on a page, and hidden phrases can be crafted to override or redirect its intended behavior. In autopilot mode, the tool acts on those instructions without requiring explicit confirmation from the user, increasing the chance that credentials or other private data get sent to an attacker-controlled location.
The Register describes this as a fresh risk for anyone relying on the CLI to handle web content. While no exploit is known to be deployed in the wild, the advice is straightforward: treat untrusted pages as a potential hazard when using the tool, and avoid autopilot mode in contexts where secrets might be at stake.