Prompt injection engineering for attackers: Exploiting GitHub Copilot(blog.trailofbits.com)
blog.trailofbits.com
Prompt injection engineering for attackers: Exploiting GitHub Copilot
https://blog.trailofbits.com/2025/08/06/prompt-injection-engineering-for-attackers-exploiting-github-copilot/
Is there any step in the chain where a repo maintainer in this case could see the full text of what was sent to Copilot in the “hidden” text?