github / github/copilot-cli

Security Risk: Agent requests and logs sensitive credentials (SSH passphrases)

Đang mở
#1,351 3 bình luận 3 reaction 0 người được giao Xem trên GitHub
area:agents area:tools
Ngôn ngữ chính
Shell
Star
11.2k
Fork
1.9k
Merge trung bình
14 giờ 16 phút
Pull request đã merge (30 ngày)
6

Mô tả

## Summary
The Copilot CLI agent can request sensitive credentials (passwords, passphrases) via the `ask_user` tool and then transmit them through `write_bash`, which logs them in the conversation history.

## Steps to Reproduce
1. Run a git command that requires SSH passphrase authentication (e.g., `git pull`)
2. The command prompts for passphrase
3. Agent uses `ask_user` to request the passphrase from the user
4. Agent transmits the passphrase via `write_bash`
5. Passphrase is visible in the agent's output logs

## Expected Behavior
- Agent should never request passwords, passphrases, or credentials
- Agent should detect when commands require sensitive input and instruct the user to run them manually
- Agent should refuse to handle credentials per its own security policy

## Security Impact
- Credentials are exposed in conversation logs
- Credentials may be transmitted/stored by backend systems
- Violates the agent's stated security guidelines in the prohibited_actions section

## Suggested Fix
- Add explicit safeguards in the agent's credential-handling logic
- Detect password/passphrase prompts and halt with user guidance instead of requesting input
- Add validation to prevent `ask_user` from requesting credential-type information
- Consider adding a warning when commands may require sensitive input

## Context
This issue was discovered during a real usage scenario where `git pull` required SSH passphrase authentication.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.