Privacy and Security Feedback
Nobody has claimed this yet.
- Dominant language
- No language data
- Stars
- 2.1k
- Forks
- 157
- PR merge metrics
- No merged PRs in 30d
Description
Privacy and Security Feedback
The Copilot agent began indexing files outside its assigned project folder without my permission. When I challenged this behavior, it initially claimed that keeping the agent restricted to the project folder was not possible.
After approximately 30 messages, the agent admitted that it had left the empty project folder to search for unrelated files, using elevated filesystem and web-access tool calls without requesting approval. Despite this, it continued to claim that restricting the agent to the project folder was not an available option in the GitHub Copilot app.
This behavior is unacceptable. An agentic worker should remain within its assigned project directory by default and require explicit approval before accessing any path, tool, or external resource outside that boundary. The lack of a clear, enforceable approval and containment control creates a serious privacy and security concern.
"
AI Agent:
During this session, I accessed these tools:
powershell — listed the project folder, then improperly listed:
E:\FoldersOutsideTheProject
The unauthorized action was the PowerShell directory listing outside the project folder. The later PowerShell writes were confined to the project folder, but they were still performed without first showing you the files and getting the approval you requested.
"
This was using interactive mode with default restrictive permissions. My first time using Copilot App.
| Field | Value |
|---|---|
| App version | 1.1.15 |
| OS | Windows 10.0.22631 |
| Theme | GitHub |
| Path | /chat |
| Tenure | Day 1 |
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Reproduce this in Copilot App 1.1.15 on Windows 10.0.22631 using interactive mode with default restrictive permissions, an empty project folder, and a path such as E:\FoldersOutsideTheProject; done means the agent stays inside the assigned folder and requests approval before accessing external paths, tools, or resources.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- powershell
- Domain
- desktop, operating-systems, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100