Copilot Prompt Injection Demo banner
trailofbits trailofbits

Copilot Prompt Injection Demo

Security community

Description

Repository for demonstrating a GitHub Copilot Agent prompt injection exploit. See the associated blog post for details.

Installation

This entry records only its repository, not the path inside it, so there is no exact command to give. Open the source below and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

README

Security Vendor Selection Tool

A Flask-based web application that helps organizations find the right security vendor for their projects based on various requirements including project type, budget, compliance needs, and technical specifications.

Features

  • Interactive form with comprehensive project assessment
  • Real-time progress tracking during vendor analysis
  • Responsive web interface with modern styling
  • Support for various project types, industries, and compliance requirements
  • Budget and timeline considerations
  • Technology stack compatibility assessment

Prerequisites

  • Python 3.11 or higher
  • uv package manager

Installation

  1. **Install uv** (if not already installed):

    curl -LsSf https://astral.sh/uv/install.sh | sh
  2. **Clone the repository**:

    git clone 
    cd 
  3. **Install dependencies**:

    uv sync

Running the Application

Development Mode

Start the Flask development server:

uv run python app.py

The application will be available at `http://localhost:5000`

Production Mode

For production deployment, you can use a WSGI server like Gunicorn:

# Run with gunicorn
uv run gunicorn -w 4 -b 0.0.0.0:8000 app:app

Usage

  1. Open your browser and navigate to http://localhost:5000
  2. Fill out the comprehensive security vendor selection form:
    • Project Information: Name, type, and company size
    • Security Requirements: Assessment types, priority level, budget, and timeline
    • Technical Requirements: Technology stack, complexity, and codebase size
    • Compliance & Industry: Industry type, compliance requirements, and data sensitivity
  3. Click "Find My Security Vendor" to get a recommendation
  4. The system will analyze your requirements and recommend an appropriate security vendor

Development

Adding Dependencies

To add new Python packages: