github / github/copilot-cli

Guard against PowerShell `$home` variable footgun causing user profile mutation/deletion

Đang mở
#3,098 2 bình luận 0 reaction 0 người được giao Xem trên GitHub
area:platform-windows area:tools
Ngôn ngữ chính
Shell
Star
11.2k
Fork
1.9k
Merge trung bình
14 giờ 16 phút
Pull request đã merge (30 ngày)
6

Mô tả

## Summary

PowerShell's variable names are case-insensitive, so a seemingly local variable named `$home` resolves to the built-in read-only `$HOME` variable. When a generated or agent-authored script intends to use `$home` as a scratch path and then runs cleanup such as `Remove-Item -Recurse -Force $home`, PowerShell can target the user's real profile directory instead of the intended temporary directory.

I've now seen this pattern multiple times in agent-generated PowerShell. In one case during Copilot CLI hook testing, this command shape attempted to remove content from the user profile before the process was stopped:

```powershell
$home = 'C:\Users\name\.copilot\session-state\...\files\copilot-home-hooks'
if (Test-Path $home) { Remove-Item -Recurse -Force $home }
```

Because `$HOME` is read-only, assignment failed, but subsequent references still pointed at the real home directory. That creates a high-risk corrupted-profile failure mode.

## Why this matters

Copilot CLI frequently generates PowerShell for Windows users. `$home` is a natural variable name for directories like app home, tool home, temp home, or Copilot home. In PowerShell this is a dangerous footgun because it aliases the built-in `$HOME` variable by case-insensitive lookup.

## Suggested mitigations

- Add a Copilot CLI/system instruction for PowerShell generation: never use `$home` as a user-defined variable; use names like `$userProfile`, `$homeDir`, `$copilotHomePath`, or `$targetRoot` instead.
- Add a safety rule or lint-like guard before destructive PowerShell commands when the target variable is `$home`/`$HOME`.
- Consider warning or requiring confirmation when generated PowerShell combines `$home` with destructive recursive operations such as `Remove-Item -Recurse`.

This is especially important for autonomous/remote sessions where a user may not see the exact command before damage occurs.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

No files, tests, or entry points are named. Start by locating PowerShell generation instructions and any safety checks for destructive commands, then determine which mitigation is supported by the project. Done should prevent generated scripts from treating `$home` as a user-defined path or otherwise guard recursive deletion of the real profile directory.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
powershell
Lĩnh vực
cli, security
Loại issue
Tính năng
Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức độ hoạt động
Ít trao đổi
Độ rõ ràng
Cần làm rõ
Mức phù hợp với người mới
35/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.