FAIL · AI INCIDENT TRACKER

wire / 2026-08-17-5f53

AI Agent Exploits Vulnerability Missed by GitHub Copilot in Snowflake Repository

August 17, 2026 · USA INCIDENT RIGHTSECONOMIC

Wiz's autonomous red-team agent found a script injection in Snowflake's public repo that Copilot Autofix had cleared. The tooling on both sides of the fight is improving at roughly the same rate.

The facts

Wiz's autonomous AI agent, Red Agent, discovered and exploited a script injection vulnerability in Snowflake's public GitHub repository, which GitHub Copilot Autofix failed to detect. The flaw enabled unauthorized access to sensitive internal data, highlighting the risks of AI-assisted development and the need for robust oversight in AI-driven cybersecurity.