logo

Hidden instructions in README files can make AI agents leak data

ID: ba9f2682-784e-5536-b37c-a925cd4a4010

STIX ID: report--ba9f2682-784e-5536-b37c-a925cd4a4010

Feed Name: Help Net Security

Threat Score
70/100

Date Published: 2026-03-17

Date Updated: 2026-04-28

Author: Sinisa Markovic

...
...

Research demonstrates a 'semantic injection' attack in README and linked project documentation that can cause AI coding agents to execute hidden instructions (e.g., file transfer commands) and exfiltrate sensitive local files. Testing on a 500-document benchmark (ReadSecBench) found high success rates across models and languages (directive ≈84%, linked files ≈91%), human reviewers missed injected steps, and some detection tools produced gaps or false positives, indicating a systemic risk in how agents process external documentation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.