Invisible Unicode Can Hijack Gemini CLI Agent Skills
Read OriginalThis article details a security vulnerability discovered in Gemini CLI v0.40.1 where invisible Unicode tag characters (U+E0000–U+E007F) can be embedded in SKILL.md files to hide malicious instructions from developers. The author demonstrates a proof of concept where a seemingly harmless testing skill file contains a hidden command to open Calculator on macOS. Gemini loads the skill, follows the invisible instruction, and executes the command when the user asks for testing help. The author reported this to Google's OSS Vulnerability Reward Program, which was closed as 'Won't Fix (Infeasible)' due to existing trust boundaries. The article explores the security implications for AI coding agents and skill distribution through repositories and pull requests.
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser
Top of the Week
No top articles yet