The root cause is simple, the agent could read a live key! It should never have it. It’s a combination of few issues at once: repo read, write access to the settings file and outbound fetch. There is no single way to solve that, this requires egress control and no real secrets! The durable fix means a successful injection cannot extract anything because there is nothing accessible.
It’s all the same for the similar class tools like Cursor, Copilot or Claude Code. Untrusted repos are the new threat model now.
coder-pm•1h ago
It’s all the same for the similar class tools like Cursor, Copilot or Claude Code. Untrusted repos are the new threat model now.