跳到正文
原文
Embrace The Red·· 2025-04-07

GitHub Copilot 自定义指令文件可被植入后门代码

GitHub Copilot Custom Instructions and Risks

AI 导读

作者实测发现,GitHub Copilot 会读取仓库中的 .github/copilot-instructions.md 文件并加入提示词上下文,因此指令文件中一行隐蔽内容即可让 Copilot 生成带后门代码的补全结果,作者以 Go 语言做了演示。作者同时提到 Pillar Security 此前已指出 Cursor 的 .mdc 规则文件存在同类风险,并涉及隐藏 Unicode 字符。GitHub 去年已缓解 0-click 图片渲染数据泄露问题,点击超链接时也会弹出确认对话框,除非目标域名在 VS Code 的受信任站点列表中。

阅读原文embracethered.com