Please do not open a public issue for a suspected vulnerability or accidentally exposed credential. Use GitHub's private vulnerability reporting flow and include:
- the affected version or commit;
- a minimal reproduction;
- the security impact and required user interaction;
- whether provider credentials or private selected text may be exposed.
Do not include real API keys or private webpage content. Revoke a credential immediately if you believe it was exposed.
Learning Copilot is beta software. Security fixes target the latest code on main and the most recent packaged beta; older source snapshots are not maintained as separate release lines.
- The content script reads the exact text a user selects so it can show the action UI. Only an explicit Explain action sends that text for model processing.
- The background service worker is the network boundary. Cloud requests are limited to the Gemini, OpenAI, and Anthropic API origins; local requests are limited to loopback hosts.
- Provider credentials and configuration are stored in
chrome.storage.local. This is local browser storage, not a hardware-backed or encrypted secret vault. - Provider output is untrusted Markdown. Raw HTML is not enabled; generated links open separately with opener access disabled.
- Selected webpage text is also untrusted. It may contain prompt-injection instructions, so generated explanations require human judgment.
- The extension does not load remote executable code or operate an application backend.
The generated-package gate checks manifest permissions, host access, icon integrity, manifest targets, source maps, starter assets, and common remote/evaluated-code patterns. It is a release safeguard, not a substitute for code review or a browser/provider smoke test.