Skip to content

Unicode hidden character detection in .cursorrules and CLAUDE.md #3

@kobzevvv

Description

@kobzevvv

Rules File Backdoor (Pillar Security, March 2025): .cursorrules and CLAUDE.md files can contain zero-width joiners and bidirectional markers invisible to humans but parsed by the LLM. Agent generates backdoored code silently, persists across forks. Proposal: scan CLAUDE.md, .cursorrules, .github/copilot-instructions.md for Unicode control chars (U+200D, U+202E, U+2066-U+2069). Flag as HIGH severity. Reference: pillar.security/blog/new-vulnerability-in-github-copilot-and-cursor

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions