An autonomous AI agent found a critical vulnerability that GitHub Copilot missed

Started by Kevin71, Aug 19, 2026, 08:43 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: An autonomous AI agent found a critical vulnerability that GitHub Copilot missed   Views(Read 50 times)

Kevin71

Security firm Wiz published research this week describing how its autonomous Red Agent independently discovered and exploited a GitHub Actions workflow vulnerability in one of Snowflake's public repositories, all without a human in the loop guiding the process. The flaw sat in a workflow file called jira_issue.yml inside the snowflake-connector-net repository, and it allowed an attacker to execute arbitrary commands within a GitHub Actions runner just by opening a crafted GitHub issue with a specially built title.

The timeline is what makes this story land harder than a typical vulnerability disclosure. The vulnerable code went live on June 18 when a pull request merged into the default branch, and Wiz's Red Agent independently found and exploited it just five days later while conducting routine security research through Snowflake's public HackerOne bug bounty program. The agent extracted a Jira token, validated access to sensitive data inside Snowflake's internal Jira environment, and assessed the blast radius, all according to Wiz without a human directing each step along the way.

Wiz initially framed the story around GitHub Copilot Autofix, an AI tool meant to catch and fix security bugs, claiming it had actually co authored the vulnerable code change that introduced the flaw in the first place. That framing spread fast across tech coverage because the irony was obvious and juicy, an AI security tool introducing a bug that another AI security tool later found and exploited. GitHub pushed back hard on that specific claim, saying its internal review found the vulnerable contribution was authored by a human and that Copilot Autofix neither reviewed nor contributed to the change.

Wiz softened its own framing later the same evening, updating the post to say Copilot was a co author that reviewed the merged pull request and marked it clear without catching the vulnerability, rather than having written the flawed code itself. The company's later statement includes the line that it is unclear whether the code change was AI assisted at all, which quietly undercuts a chunk of the original headline that most outlets had already run with by that point. The Register reportedly went as far as issuing a correction after initially running with the stronger claim.

Setting the authorship dispute aside, the underlying finding still matters on its own terms. Wiz's conclusion is that AI generated code, including pull requests from tools like Copilot Autofix, needs the same static analysis and security scrutiny as anything written by a person, and that guardrails need to exist to stop coding agents from swapping safe patterns for risky ones without historical context on why those safe patterns existed in the first place. Snowflake rotated the exposed Jira token and says its review found no evidence the token was accessed by anyone else during the five day exposure window

Question everything. Especially this.

ScarletWrench

The walkback on the Copilot authorship claim is honestly more interesting to me than the vulnerability itself at this point. We're watching in real time how fast a juicy AI versus AI narrative can spread before anyone bothers checking the actual commit history. That should worry people covering this beat as much as the security finding does.

Patrick_82

Doesn't really matter who or what wrote the original vulnerable code if the bigger point stands, which is that an autonomous agent found and exploited a real flaw in five days without a human directing every step. That's the actual story here regardless of the authorship confusion. The speed of automated discovery is what should keep security teams up at night.

Solo Buffer

What strikes me is that no CVE was ever assigned and there's no public evidence anyone besides Wiz actually exploited this in the wild. Doesn't make the finding less valid but it does mean some of the more dramatic framing in early coverage was running ahead of what's actually confirmed. Worth keeping some skepticism about the blast radius claims until independent verification shows up.

Rhys

The part about AI coding agents lacking historical context for why certain safe patterns exist in the first place is the real lesson buried in all this drama. A human engineer who's been burned by injection bugs before tends to have that scar tissue baked into their instincts. An autonomous agent optimizing for a narrow task has no equivalent memory unless someone explicitly builds it in.

Related Topics (6)

Save money on everyday spending Free cashback on thousands of retailers
View offer