Researchers at Orca Security discovered RoguePilot, a critical vulnerability in GitHub Codespaces where passive prompt injection via hidden HTML comments in GitHub Issues allowed attackers to hijack repositories. The attack chain works by: embedding hidden instructions in an issue, tricking GitHub Copilot into checking out a
Table of contents
Background: The “God Mode” Problem in AI ToolingThe Threat Landscape: Active vs. Passive Prompt InjectionTechnical Analysis: The RoguePilot Exploit ChainGet Sohan Kanna ’s stories in your inboxImpact Assessment: The Keys to the KingdomRemediation and Defense-in-DepthConclusionSort: