logoalt Hacker News

What I learned by putting GitHub Copilot behind a MitM proxy

43 pointsby j0selit0today at 10:40 AM4 commentsview on HN

Comments

j0selit0today at 11:16 AM

I was curious to understand how Copilot implements its harness, and also how I was exhausting my quota so quickly. End up going down a rabbit hole of intercepting its network traffic with mitmproxy.

A few interesting things I found along the way:

- watched model/capability discovery and routing happen in real time - looked at what gets injected into context and sent with ghost completions - found that recent edits can pull in context from files other than the one you're currently editing (including infamous .env) - found the SQLite session store behind Chronicle, including previous prompts/responses - watched the model query that history through tool calls

I then went through the VS Code source to reconcile some of what I was seeing on the wire with the actual implementation.

Overall some interesting lessons around how their harness is implemented.

ameliaquiningtoday at 2:12 PM

Minor factual correction: The Codex client is open source. https://github.com/openai/codex

tolugeniustoday at 2:06 PM

Nice deep dive, I always wondered how copilot worked compared to similar tools. I'm shocked at the lack of of a rule for env files, I at least thought with a tool more integrated with github as a whole that would be a default but alas.

bartek_gdntoday at 1:33 PM

Nice one! Really shows why we should run those in sandboxes without env access. I like the proxy swap approach