Public disclosure forces a Copilot Plugin4Shell fix within a month
Why I called it
AIR disclosed privately in June and Microsoft shipped nothing in three months. Public disclosure changes the calculus: the exploit recipe is published, Anthropic and OpenAI have both patched, and an unpatched in a flagship developer product costs more reputation every day it stays open. Vendors move when silence costs more than the fix.
The call, in full. GitHub ships a Copilot patch or mitigation for the Plugin4Shell SHA-pinning bypass on or before October 20th 2026.
Scoring criterion. RESOLVES CORRECT if, on or before 2026-10-20 23:59 UTC, GitHub or Microsoft publishes a release note, security advisory or changelog entry for GitHub Copilot ( or IDE integrations) that fixes or mitigates the Plugin4Shell SHA-pinning bypass disclosed by AIR Security. RESOLVES WRONG otherwise.
The criterion is the machine-checkable version: a prediction that cannot be settled by a third party against a public source fails the build before it reaches this page.