Liran Tal 7/17/2026

Invisible Unicode Can Hijack Gemini CLI Agent Skills

Read Original

This article details a security vulnerability discovered in Gemini CLI v0.40.1 where invisible Unicode tag characters (U+E0000–U+E007F) can be embedded in SKILL.md files to hide malicious instructions from developers. The author demonstrates a proof of concept where a seemingly harmless testing skill file contains a hidden command to open Calculator on macOS. Gemini loads the skill, follows the invisible instruction, and executes the command when the user asks for testing help. The author reported this to Google's OSS Vulnerability Reward Program, which was closed as 'Won't Fix (Infeasible)' due to existing trust boundaries. The article explores the security implications for AI coding agents and skill distribution through repositories and pull requests.

Invisible Unicode Can Hijack Gemini CLI Agent Skills

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week

No top articles yet