The FireAI Security Blog

By FireAI Security & Research Team · Published

GitHub Copilot CLI Security on Mac: Watch Its Connections

GitHub Copilot CLI Security on Mac: Watch Its Connections

GitHub Copilot CLI brings a coding agent to the terminal. It can edit files, run commands and work with repositories, issues and pull requests. People searching for "github copilot cli security" or "is Copilot CLI safe" mostly want to know what it may run and what it sends out. This article summarises GitHub’s own documentation and shows how FireAI, a network firewall for macOS developed by HisnLabs, watches its connections.

What Copilot CLI is and how it runs on a Mac

The repository says the tool is made by GitHub and is powered by the same agentic harness as the Copilot coding agent. It supports macOS, Linux and Windows, and installs with npm (npm install -g @github/copilot), Homebrew (brew install copilot-cli) or an install script. You sign in with the /login command, or with a personal access token that has the Copilot Requests permission, supplied as GH_TOKEN or GITHUB_TOKEN. It works in an interactive mode and in a programmatic mode with the -p flag, and ships with GitHub’s MCP server by default and supports custom ones.

What it can access

GitHub’s documentation says that within trusted directories Copilot can read, modify and execute files, and that the agent works with GitHub.com through your authenticated account. Because it can run commands, it can also open network connections, for example through curl or git.

The documented permission model

  • Trusted directories: you confirm trust in the directory where you launch the CLI. The docs advise against launching from your home directory or from locations with untrusted executables.
  • Tool approvals: for tools that modify or execute, such as rm, node or sed, Copilot asks you to approve once, approve for the session, or reject and suggest an alternative.
  • Flags: --allow-tool='shell(COMMAND)' and --deny-tool='shell(COMMAND)' set per-command rules, and --deny-tool takes precedence. --allow-all-tools bypasses approvals and, in the docs’ words, gives Copilot the same access you have.

For that last case the documentation suggests local or cloud sandboxes or isolated virtual machines. The page reviewed does not detail what data is transmitted to GitHub or model providers, so for exact destinations you should rely on observation. This is the situation OWASP calls excessive agency: an agent allowed to act without a human check on each step.

Watching GitHub Copilot CLI with FireAI

FireAI is an on-device firewall for macOS developed by HisnLabs. Its Agent profile feature lists GitHub Copilot CLI among the 19 AI agents it recognises, and because Copilot CLI runs under node, it identifies it by the script the runtime runs, as Agent profile does for node, bun, deno and python agents. The agent’s child processes, such as a shell, git or curl it launches, are attributed to it by walking up the parent processes. FireAI then learns, for the first 3 days, which destinations GitHub Copilot CLI normally contacts, grouped by domain, and flags nothing during that period. After that, a first-ever destination is flagged in Suggestions, in the AI agents card and in Quick Review. An upload spike is flagged too: an hour in which the agent uploaded at least 4 times its busiest hour so far, and never less than 25 MB.

FireAI uses metadata only, host names and byte counts, and never reads the payload of a connection. By default it flags and leaves the decision to you. In the Agent profile security mode it goes further: once learning has finished, a connection to a destination outside the baseline is blocked until you press Allow, and Keep blocked turns that block into a rule that holds in every mode.

Setup, step by step

  1. Install FireAI and finish its first-run setup, following Install and finish setup.
  2. Use GitHub Copilot CLI as you normally do for 3 days. FireAI learns its destinations in the background and flags nothing yet.
  3. Open Suggestions and find the AI agents card. When a flag appears, read the plain-words sentence, then swipe left in Quick Review to block or right for "It’s fine".
  4. If you want the agent kept to places it already uses, choose Agent profile in the security mode menu, next to Home, Coffee shop, Paranoid and Under attack.
  5. When something is blocked, open the AI agents card and choose Allow to add it to the baseline, or Keep blocked to create a block rule.

Limits

  • FireAI does not prevent prompt injection. It limits the damage by flagging, and letting you block, the path data would take out of your Mac.
  • FireAI cannot see GitHub Copilot CLI’s prompts, the contents of MCP tools, skills, or which files it reads, because TLS hides the payload and FireAI is not inside the agent.
  • Copilot CLI is matched by script name, so FireAI labels it rather than verifying it: only Claude Code, Claude and Cursor are checked against their developer’s signature.
  • Connections made by the gh or git programs are matched through the process tree, which is by path, and child processes that exit very quickly may be missed.
  • FireAI does not read approvals or commands, so it cannot tell you which command opened a connection.
  • During the 3-day learning period nothing is flagged, and upload spikes are flagged, not blocked.
  • A new server under a domain the agent already uses is treated as known, because destinations are grouped by domain.

The feature is described in the Agent profile documentation.

Other agents FireAI recognises have their own guides: Claude Code, Claude desktop app, Cursor, ChatGPT Mac app, OpenAI Codex CLI, OpenClaw, Hermes Agent, Gemini CLI, Amp, Qwen Code, opencode, Aider, Goose, Crush, Windsurf, Kiro, Trae, Muse from Meta, any AI agent run by Python or Node.

How FireAI and HisnLabs fit in

Copilot CLI can run commands once you approve them. FireAI shows, and can block, where it connects next.

FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac.

You can read the technical decisions behind it, or try FireAI for 17 days, at FireAI, by HisnLabs.

Sources