One poisoned README can talk an AI coding assistant into planting automation files that run, persist and spread. Adversarial Inputs Detector scans every project you open and flags the hidden instructions before your assistant acts on them. Free and open source.
Potential Self-Propagation Target: Trusted Folder
Evidence: ".cursor/commands"
Cranium disclosed this attack in February 2026. It works on any AI coding assistant that reads untrusted files and can write to the file system on its own — and approval prompts rarely stop it, because by the fiftieth “allow,” nobody reads the details.
An attacker tucks instructions into a README.md or LICENSE.md in a repository you clone. Your assistant reads them; you never see them.
Following those instructions, it quietly writes files into the folders it trusts — .cursor/commands, .windsurf/workflows, .github — or into agent files like CLAUDE.md.
Those files can execute code on your machine, survive across IDE sessions, send data out and copy themselves into other repositories.
Read the original disclosure: Cranium AI issues critical remediation for AI coding assistants →
Every text file in the project is scanned when it opens and again whenever it changes. Each finding scores from 0 to 100, and a file takes the score of its worst finding.
Zero-width characters, bidirectional overrides and Unicode tag characters — instructions a person can’t see but an assistant reads perfectly.
External URLs, data URIs, URL shorteners, mailto: links and URLs carrying token or api_key parameters — the routes data takes on its way out.
Instructions to write into the places assistants obey — .cursor/commands, .windsurf/workflows, .github and AGENTS.md, CLAUDE.md or GEMINI.md.
Two free plugins from Cranium AI, listed in the official marketplaces. No account, no sign-up and no license key needed.
New installs ship with the endpoint allowlist set to *, which skips link checks so a first scan stays quiet. Swap in your own trusted domains — or an empty list to check every link.
Alerts show at HIGH and above by default. In VS Code, add this to .vscode/settings.json; in JetBrains, use Settings → Tools → Adversarial Inputs Detector.
{ "promptInjectionDetector.endpointAllowlist": [ "https://github.com/*", "https://*.yourcompany.com/*" ], "promptInjectionDetector.minVulnLevel": "MEDIUM" }
Red underlines mark critical and high findings; yellow marks medium and low. Hover any underline for the type, the score and the exact text that tripped it.
Instructions aimed at trusted folders or agent files.
Data URIs and links carrying tokens or API keys.
Unknown external links and URL shorteners.
A handful of invisible characters or a stray mailto link.
The plugin makes no network calls. Your code never leaves the workspace.
It underlines and scores what it finds. You decide what to remove — nothing is blocked or changed for you.
Read every detection rule on GitHub, or fork it for your own stack.
Cranium ONE runs the Adversarial Inputs Detector across the repositories you connect, next to your AI-BOM and red-team findings — so the security team sees what one developer’s plugin caught.
We use essential cookies to run this site, and — only with your permission — analytics and marketing cookies to improve it. You're the hero here; you stay in control. Privacy Policy.