Hidden instructions in README files can make AI agents leak data
ID: ba9f2682-784e-5536-b37c-a925cd4a4010
STIX ID: report--ba9f2682-784e-5536-b37c-a925cd4a4010
Feed Name: Help Net Security
Research demonstrates a 'semantic injection' attack in README and linked project documentation that can cause AI coding agents to execute hidden instructions (e.g., file transfer commands) and exfiltrate sensitive local files. Testing on a 500-document benchmark (ReadSecBench) found high success rates across models and languages (directive ≈84%, linked files ≈91%), human reviewers missed injected steps, and some detection tools produced gaps or false positives, indicating a systemic risk in how agents process external documentation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
