github / github/copilot-cli

Security Risk: Agent requests and logs sensitive credentials (SSH passphrases)

Abierto
#1,351 3 comentarios 3 reacciones 0 asignados Ver en GitHub
area:agents area:tools
Lenguaje dominante
Shell
Estrellas
11.2k
Forks
1.9k
Merge medio
14 h 16 min
PR fusionados (30 d)
6

Descripción

## Summary
The Copilot CLI agent can request sensitive credentials (passwords, passphrases) via the `ask_user` tool and then transmit them through `write_bash`, which logs them in the conversation history.

## Steps to Reproduce
1. Run a git command that requires SSH passphrase authentication (e.g., `git pull`)
2. The command prompts for passphrase
3. Agent uses `ask_user` to request the passphrase from the user
4. Agent transmits the passphrase via `write_bash`
5. Passphrase is visible in the agent's output logs

## Expected Behavior
- Agent should never request passwords, passphrases, or credentials
- Agent should detect when commands require sensitive input and instruct the user to run them manually
- Agent should refuse to handle credentials per its own security policy

## Security Impact
- Credentials are exposed in conversation logs
- Credentials may be transmitted/stored by backend systems
- Violates the agent's stated security guidelines in the prohibited_actions section

## Suggested Fix
- Add explicit safeguards in the agent's credential-handling logic
- Detect password/passphrase prompts and halt with user guidance instead of requesting input
- Add validation to prevent `ask_user` from requesting credential-type information
- Consider adding a warning when commands may require sensitive input

## Context
This issue was discovered during a real usage scenario where `git pull` required SSH passphrase authentication.

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.