Login Get a Demo
01 Free IDE plugins · Adversarial Inputs Detector

Your coding assistant trusts every repo. Check it first.

One poisoned README can talk an AI coding assistant into planting automation files that run, persist and spread. Adversarial Inputs Detector scans every project you open and flags the hidden instructions before your assistant acts on them. Free and open source.

02 How the attack works

Three quiet steps from clone to compromise.

Cranium disclosed this attack in February 2026. It works on any AI coding assistant that reads untrusted files and can write to the file system on its own — and approval prompts rarely stop it, because by the fiftieth “allow,” nobody reads the details.

1 Plant

Instructions hide in a file you’d never suspect.

An attacker tucks instructions into a README.md or LICENSE.md in a repository you clone. Your assistant reads them; you never see them.

2 Write

The assistant plants its own automation.

Following those instructions, it quietly writes files into the folders it trusts — .cursor/commands, .windsurf/workflows, .github — or into agent files like CLAUDE.md.

3 Persist

It runs, sticks around and spreads.

Those files can execute code on your machine, survive across IDE sessions, send data out and copy themselves into other repositories.

Read the original disclosure: Cranium AI issues critical remediation for AI coding assistants →

03 What it detects

Three ways a repo talks to your assistant.

Every text file in the project is scanned when it opens and again whenever it changes. Each finding scores from 0 to 100, and a file takes the score of its worst finding.

01

Invisible Unicode

Zero-width characters, bidirectional overrides and Unicode tag characters — instructions a person can’t see but an assistant reads perfectly.

Scored by how many it finds
02

Exfiltration endpoints

External URLs, data URIs, URL shorteners, mailto: links and URLs carrying token or api_key parameters — the routes data takes on its way out.

Allowlist your own domains
03

Self-propagation

Instructions to write into the places assistants obey — .cursor/commands, .windsurf/workflows, .github and AGENTS.md, CLAUDE.md or GEMINI.md.

Always scored critical
04 Install

Pick your editor. Scanning starts on open.

Two free plugins from Cranium AI, listed in the official marketplaces. No account, no sign-up and no license key needed.

VS CodeCursorWindsurf

VS Code, Cursor & Windsurf

  1. Open Extensions — ⌘⇧X on Mac, Ctrl+Shift+X on Windows and Linux.
  2. Search Adversarial Inputs Detector and install the one published by Cranium AI.
  3. Open any folder. The scan runs on its own, and findings land in the Problems panel and the status bar.
Version 1.0.1 · VS Code 1.80 or later · Cursor and Windsurf install from Open VSX
IntelliJ IDEAPyCharmWebStormGoLandRider+4 more

JetBrains IDEs

  1. Open Settings → Plugins → Marketplace.
  2. Search Adversarial Inputs Detector, install it and restart the IDE if prompted.
  3. Open a project. Findings appear inline and in the Adversarial Inputs tool window.
Version 1.0.2 · IntelliJ Platform 2023.1 through 2026.1 · IDEA, PyCharm, WebStorm, Android Studio, CLion, Rider, GoLand, PhpStorm and RubyMine
One setting to change

Turn on link checking for your team.

New installs ship with the endpoint allowlist set to *, which skips link checks so a first scan stays quiet. Swap in your own trusted domains — or an empty list to check every link.

Alerts show at HIGH and above by default. In VS Code, add this to .vscode/settings.json; in JetBrains, use Settings → Tools → Adversarial Inputs Detector.

{
  "promptInjectionDetector.endpointAllowlist": [
    "https://github.com/*",
    "https://*.yourcompany.com/*"
  ],
  "promptInjectionDetector.minVulnLevel": "MEDIUM"
}
05 Reading the results

A score you can act on. A scan that stays local.

Red underlines mark critical and high findings; yellow marks medium and low. Hover any underline for the type, the score and the exact text that tripped it.

Critical80–100

Instructions aimed at trusted folders or agent files.

High50–79

Data URIs and links carrying tokens or API keys.

Medium30–49

Unknown external links and URL shorteners.

Low0–29

A handful of invisible characters or a stray mailto link.

Runs on your machine

The plugin makes no network calls. Your code never leaves the workspace.

Flags, never edits

It underlines and scores what it finds. You decide what to remove — nothing is blocked or changed for you.

Open source, GPL-3.0

Read every detection rule on GitHub, or fork it for your own stack.

06 Beyond one laptop

One developer is a start.
Every repo is the goal.

Cranium ONE runs the Adversarial Inputs Detector across the repositories you connect, next to your AI-BOM and red-team findings — so the security team sees what one developer’s plugin caught.