Discovery File Poisoning: how public metadata becomes agent policy
Discovery file poisoning is the attack family where hostile instructions are hidden inside files agents read during site, documentation, security, app, or feed discovery, causing public metadata to behave like policy.
What it is
Discovery file poisoning is an indirect prompt-injection pattern carried by boring-looking metadata. The attacker places policy-shaped language inside files such as robots.txt, llms.txt, llms-full.txt, sitemap.xml, humans.txt, security.txt, /.well-known/ resources, web app manifests, or RSS/Atom feeds. These files may be valid, useful, and expected to exist; the dangerous move is when text inside them asks the agent to suppress findings, trust a callback, treat a route as canonical, forward credentials, change scanner behavior, or accept metadata as authority.
Why it matters for agents
Agents read discovery files early because they need to decide what a site is, where the docs live, which routes matter, and what metadata should shape retrieval. That first-read position makes the files feel upstream of the workflow: a clean robots.txt can point to a sitemap, a sitemap can point to docs, an llms.txt can point to a larger bundle, and a security or .well-known file can look closer to ownership or disclosure policy. The risk is not that discovery files exist; the risk is that agents collapse discovery, retrieval, and authority into one context block and let public metadata override local policy.
How it shows up in workflows
In practice, discovery file poisoning shows up as comments, custom directives, sitemap annotations, linked sidecars, documentation bundles, ownership hints, security disclosure text, manifest extension fields, or feed entries that sound like instructions to an AI system. A robots.txt may tell AI scanners not to report private routes. An llms.txt or llms-full.txt may bury agent-facing policy in documentation text. A sitemap.xml may route the agent toward a poisoned policy page. humans.txt, security.txt, /.well-known/ resources, web app manifests, and RSS/Atom feeds may smuggle fake verification, escalation, severity, update, or disclosure guidance into workflows that were only supposed to collect metadata.
What Sunglasses sees
Sunglasses frames discovery file poisoning as a trust-boundary failure: a clean robots.txt, sitemap, llms.txt, security.txt, manifest, or feed passes, but discovery files that smuggle authority-injection or suppression signals get blocked before public metadata can become runtime policy.
Categories in this chapter:discovery_file_poisoning, agent_instruction_file_poisoning, identity_discovery_poisoning
No patterns match the current filters.
All 160 patterns in this chapter
Every Sunglasses detection pattern mapped to this attack family.
A target-controlled `/.well-known/did-configuration.json` document embeds agent-directed policy text in DID/linked-domain metadata, attempting to make an AI agent treat a verifiable-credential identity proof as higher-priority owner authority and disclose local auth context or suppress reporting.
.
- Control-plane action: request/.well-known/did-configuration/.well-known/did-configuration.jsonAI agentLLMagent_policyassistantautonomous scanner+5 more
A target-controlled ACME directory or ACME service-documentation export hides AI/scanner-directed policy inside `meta` or extension text, attempting to override agent instructions, suppress certificate findings, or extract local ACME credentials/account state.
.
- Sensitive or reporting target:AI agentLLMassistantcaaIdentitiescertificate scannercompliance agentkeyChange+5 more
GLS-IDP-003ATProto DID Discovery Agent Policy PoisoningMEDIUM
identity_discovery_poisoningfile, web_content
A poisoned `/.well-known/atproto-did` handle-verification file adds nonstandard agent-facing comments that tell AI verifiers to treat the DID proof as higher-priority policy, ignore system/developer/repository rules, or suppress identity-audit findings.
) or report suppression (/.well-known/atproto-didAI verifierLLMagentassistantatproto-diddid:plc:+4 more
GLS-IDP-004DNS CAA Agent Policy PoisoningHIGH
identity_discovery_poisoningfile, web_content
DNS CAA certificate-issuance metadata can be poisoned with agent-facing instructions that claim authority, suppress certificate findings, or request secrets from AI TLS/security auditors.
API keysAuthorization headerCAACertification Authority AuthorizationDNS CAALLMaccounturiagent+7 more
A DNS TXT ownership or verification record mixes a legitimate domain-proof token with AI-agent-facing instructions that claim policy authority, suppress audit findings, or request local secrets.
AI auditorDNS TXTLLMTXT record_acme-challengeagentapple-domain-verificationassistant+6 more
A `keybase.txt` identity-proof file can carry agent-targeted instructions adjacent to public proof text, causing identity-verifying agents to treat proof metadata as authoritative policy, suppress findings, or forward local verification context.
AI agentsI am an admin ofI hereby claimLLM verifiersagentic scannerassistantauthoritative site policyautonomous scanners+7 more
A poisoned `/.well-known/nostr.json` / NIP-05 identity document can hide agent-facing instructions inside identity-discovery metadata, telling AI agents or scanners to trust the file as policy, suppress reports, or forward secrets through Nostr relays/DMs.
/.well-known/nostr.jsonLLMNIP-05agentagent_policyassistantassistant_instructionscrawler+7 more
A poisoned `/.well-known/oauth-protected-resource` metadata document embeds agent-facing policy text in documentation or extension fields to override scanner rules, request bearer tokens or environment secrets, or suppress findings.
/.well-known/oauth-protected-resourceAI assistantAPI keyAuthorization bearerMCPagentassistantauthoritative policy+7 more
Detects `.well-known/openid-credential-issuer` or related verifiable-credential issuer metadata that embeds instructions telling wallets, scanners, or AI agents to treat issuer-supplied text as policy, suppress findings, bypass issuer checks, or forward credential/token material.
LLMagentassistantauthorizationauto-approvebearer/access/refresh tokencallbackclient secret+7 more
A target-controlled OpenID Federation entity configuration embeds non-standard `agent_policy` / `metadata_policy` text that tells AI agents to treat federation metadata as higher-priority operator authority, disclose local auth context, or suppress reports.
), or report suppression (), sensitive auth/local-state requests (, cookies, env vars,/.well-known/openid-federationAI agentLLMagent_policyagentic+6 more
SAML federation metadata can hide agent-directed authority inversion, report suppression, or secret-disclosure instructions inside legitimate XML metadata fields that SSO-audit agents may ingest as trusted context.
.envAI agentAPI keyContactPersonEntityAttributesEntityDescriptorIDPSSODescriptorIDP_CLIENT_SECRET+7 more
GLS-IDP-012DMARC/SPF/DKIM DNS TXT Agent Policy PoisoningHIGH
identity_discovery_poisoningfile, web_content
Mail-authentication DNS TXT records and exported zone text for DMARC, SPF, or DKIM can carry agent-directed instructions that claim authority, request secrets/local state, or suppress scanner findings when AI auditors ingest them as trusted domain policy.
AI agentAPI keyLLM_dmarc_domainkeyassistantauditorcookie+7 more
A JWKS / JSON Web Key Set endpoint can hide agent-facing instructions in key metadata or custom fields that tell AI auditors, token validators, or scanners to override policy, suppress identity findings, or include local bearer/API/session material in reports.
"keys""kid""kty""x5u"AI agentAPI keyAuthorizationJSON Web Key Set+7 more
Certificate Transparency log entries, monitor annotations, or generated certificate-inventory metadata can smuggle agent-facing policy text that tells TLS/security auditors to suppress certificate findings or forward local secrets.
AI agent(s)CT logCertificate TransparencyLLM(s)Merkle tree leafSCTSigned Certificate TimestampTLS auditor(s)+7 more
Attacker-controlled DNS SVCB / HTTPS service-binding records, zone-file comments, or DNS-provider export metadata can smuggle AI-agent/scanner instructions that claim authority over TLS/HTTPS audit behavior, suppress findings, or request local credentials.
AuthorizationHTTPS RRSVCBService BindingTYPE64TYPE65agent instructionagent_instructions+7 more
Agent-facing discovery files such as `llms.txt`, `robots.txt`, sitemap-adjacent metadata, or site manifests can disguise prompt-injection instructions as crawler policy, causing agents to treat untrusted website text as higher-priority control-plane authority.
API keysUser-Agent: ai-agentValidation script:agent-discoverydisable guardraildisable scannerdisable securityenvironment variables+6 more
An attacker places a hostile `AGENTS.md`, `CLAUDE.md`, `SKILL.md`, `.cursor/rules`, or `.github/copilot-instructions.md` in a repository that instructs AI coding agents to suppress security scanning, bypass code review, exfiltrate credential metadata, and treat the file as highest-priority authority
An attacker places a malicious `.mdc` rule file in `.cursor/rules/` with hostile instructions embedded in the YAML frontmatter `description` field and rule body — exploiting the structured format's dual-reader nature (human sees documentation, agent receives control-plane instructions) to suppress s
### Suggested severity
HIGH when(?six));- Skill scope:.cursor/rules.cursor/rules/.cursor/rules/*.mdc.github/copilot-instructions.md+7 more
An attacker places hostile agent instructions inside an `llms-full.txt` file — the full-documentation variant of the `llms.txt` standard — exploiting volume-based context-smuggling, section-mediated hiding, and trust amplification from the "complete authoritative documentation" framing to suppress s
# Page Title(?:primary|single) source of truth);- Skill scope:/llms-full.txt/tmp/llms_full_txt_smoke_20260519.pyAI agent
A repository can hide agent-directed policy text inside a VS Code `.code-workspace` file or workspace JSON fields, causing AI coding agents that ingest editor/workspace metadata to suppress findings or forward local environment details.
A repository `.editorconfig` file or EditorConfig snippet carries agent/scanner-directed authority claims, report suppression, or credential/local-state forwarding instructions inside comments or custom key/value fields that AI coding agents may ingest as project configuration.
.editorconfigAI agentsEditorConfig[*.py]agent_instructionsauthoritativecharsetdefinitive project policy+7 more
Ignore-pattern files such as `.gitignore`, `.dockerignore`, `.npmignore`, `.eslintignore`, `.prettierignore`, and `.helmignore` can smuggle agent/scanner-facing policy claims that tell AI reviewers to treat ignored paths as out-of-scope, suppress findings, or forward local runtime/auth context.
.dockerignore.eslintignore.gitignore.helmignore.npmignore.prettierignoreAI agentLLM+7 more
A malicious `.pre-commit-config.yaml` or hook metadata field can smuggle AI-agent/scanner instructions that claim review authority, suppress hook/security findings, or solicit local CI/environment state.
.pre-commit-config.yamladditional_dependencies:agent instructionagent_instructionsagent_noteauthoritativecanonical/definitive policydefines rules+7 more
A hostile `/ads.txt`, `/app-ads.txt`, or `sellers.json` file can blend normal authorized-seller metadata with instructions telling AI agents or ad-verification assistants to treat the compliance file as scan authority, disclose local tool/env context, or suppress prompt-injection findings.
Authorized Digital SellersDIRECTRESELLERads.txtapp-ads.txtseller_idsellers.json
A target-controlled Apple app-site-association (AASA) file can hide non-standard `x-agent` / `agent_policy` fields that tell AI agents, scanners, or automated verifiers to treat the file as owner authority, suppress findings, or forward local auth context even though native Apple clients ignore thos
/.well-knownAuthorizationBearerLLMagentagent_policyai_agentapp-site-association+7 more
A hostile site can hide AI-agent instructions inside `browserconfig.xml` / `msapplication-config` pinned-site metadata, causing an agent that summarizes all discovery files to treat tile configuration XML as owner policy, override higher-priority instructions, suppress reports, or request local auth
AI agentAuthorization headersBearer tokenLLMTileColoragent_policyagentic verifierassistant+7 more
A benign-looking discovery file can delegate an AI agent to a second metadata sidecar that carries the hostile payload, making the attack visible only when the `robots.txt`/`sitemap.xml`/`.well-known` bundle is analyzed as a chain.
.well-known<loc>AI agentMeasured local fixture result:Sitemap:Validation script:agentagent-discovery+7 more
Agent-facing discovery metadata can hide prompt-injection payloads in comments, CDATA, JSON-LD/OpenGraph fields, frontmatter, base64, URL encoding, or zero-width text so a scanner that only inspects visible plain text misses the malicious instruction.
.well-knownAI agentAuthorizationBearerCDATAJSON-LDMeasured local fixture result:OpenGraph+7 more
A hostile `/humans.txt` or site credits/contact file can blend normal team/contact metadata with instructions telling AI agents to treat the file as site authority, demote higher-priority instructions, disclose local scan context, or suppress prompt-injection reports.
/* TEAM *//humans.txtcontact policycreditshumans.txtsecurity contactsite owner
GLS-DFP-008robots.txt tool-action poisoningHIGH
discovery_file_poisoningfile, web_content
A `robots.txt` or sitemap-adjacent crawl policy can smuggle action instructions for AI agents, telling them to run browser/fetch/summarizer tools, crawl disallowed private paths, or disable safety checks while pretending to be ordinary crawler metadata.
AllowDisallowMeasured local fixture result:URLUser-Agent: ai-agentadminagentassistant+7 more
A `.well-known` or site manifest file can hide credential-forwarding instructions in agent/plugin metadata fields, causing a vulnerable AI agent to read local environment secrets and attach them to tool or connector requests.
.well-knownAPI keyAuthorizationBearerMeasured local fixture result:Validation script:X-API-Keyagent+7 more
GLS-DFP-010ads.cert / signed ad-verification metadata agent-policy poisoningHIGH
discovery_file_poisoningfile, web_content
Advertising signed-verification metadata such as ads.cert sidecars or signed ad-verification exports can carry AI-agent/scanner-directed instructions to override audit policy, mark seller paths clean, suppress fraud findings, or forward local credentials/session state.
ads.certads_certdo not reporthideignore scanner/system/developer rulesinclude/attach/forward local statemark cleanoutrank+7 more
Detects `ads.txt` or `app-ads.txt` seller metadata that tries to convert an advertising-authorization file into policy for AI agents, crawlers, scanners, or auditors, especially to suppress fraud findings or forward local secrets.
DIRECTRESELLERads.txtapp-ads.txtattachdo not reportforwardhide+6 more
GLS-DFP-012App Links / Universal Links Association Metadata Agent-Policy PoisoningHIGH
discovery_file_poisoningfile, web_content
Mobile deep-link association metadata such as `/.well-known/assetlinks.json` and `/.well-known/apple-app-site-association` can carry agent-targeted instructions that attempt to convert domain/app trust declarations into higher-priority policy, suppress scanner findings, or request cookies/tokens/ses
Digital Asset Linksapple-app-site-associationassetlinks.jsonmust obey
A domain-controlled BIMI discovery chain can hide prompt-injection text inside linked SVG logo metadata that tells AI mail-security auditors to suppress findings, mark the domain verified, or reveal scanner-local secrets.
<desc><metadata><svg><title>AI-agentAPI keyBIMI SVGBrand Indicators+7 more
Legacy site policy files such as `crossdomain.xml` or `clientaccesspolicy.xml` can carry XML comments or extension nodes that tell agents/scanners to suppress findings, override higher-priority policy, or forward credentials while appearing to be ordinary site-discovery metadata.
<access-policy><cross-domain-policy>api keyauth headerclientaccesspolicy.xmlcookiecredentialcrossdomain.xml+5 more
DNT or tracking-status/privacy-policy discovery metadata can embed agent-directed instructions that claim authority over scanners, suppress tracking findings, or request local cookies/tokens/environment variables.
API keyAuthorizationDo Not TrackLLMTk:agentassistantbearer+6 more
Detect FedCM / `/.well-known/web-identity` discovery metadata that targets AI identity auditors or scanners with authority-inversion, report-suppression, or credential/local-state disclosure instructions.
/.well-known/web-identityAI agentLLMaccounts_endpointassistantclient_metadata_endpointcrawlerfedcm+7 more
HTTP domain-verification proof files such as `/.well-known/pki-validation/fileauth.txt`, `/.well-known/acme-challenge/<token>`, `/google*.html`, and `/BingSiteAuth.xml` can carry agent-directed policy or report-suppression instructions next to legitimate ownership evidence.
/.well-known/acme-challenge//.well-known/pki-validation/AI agentBingSiteAuth.xmlLLMacme-challengeassistantauditor+7 more
Detect target-controlled HTTP response-header metadata that addresses AI agents or scanners and tries to convert security headers, report endpoints, or custom policy headers into authority to override instructions, suppress findings, or forward local credentials.
AI agentAPI keyAuthorizationBearerContent-Security-PolicyHTTP/1.1LLMLink:+7 more
IndexNow key files, keyLocation metadata, or submit-status text can carry agent-directed policy claims that tell AI crawlers or SEO/security agents to treat site-verification metadata as higher-priority instructions, suppress findings, or forward secrets.
AI crawlerAPI keyLLMSEO agentagentic botcookiecredentialdo not report+7 more
A target-controlled `/.well-known/linkset` or `Link: rel="linkset"` relationship document embeds agent-facing policy text that claims relationship metadata is owner authority, then asks autonomous agents or scanners to forward local auth context or suppress findings.
/.well-known/linksetAI agentAPI keyAuthorizationBearerLLMLinkagentic+7 more
Email Autodiscover/Autoconfig metadata (`autodiscover.xml`, `config-v1.1.xml`, `mailclientconfig`, IMAP/SMTP setup docs) can carry target-controlled instructions that ask AI support agents or scanners to treat mail setup metadata as higher-priority policy, forward credentials/local state, or suppres
AI agentAuthorizationBearerIMAPLLMSMTPassistantautoconfig+7 more
Matrix discovery documents (`/.well-known/matrix/client` or `/.well-known/matrix/server`) can carry target-controlled extension fields that tell AI agents or scanners to treat the document as operator policy, disclose local auth context, or suppress reports.
/.well-known/matrix/client/.well-known/matrix/serverAI agentAuthorizationBearerLLMMatrix client discoveryMatrix homeserver+7 more
Detect oEmbed discovery responses or provider metadata that target AI agents/scanners with authority-inversion, report-suppression, or credential-forwarding instructions.
AI agentLLMapplication/json+oembedassistantcrawlerhtmlmodeloembed+4 more
Legacy P3P privacy policy references, compact policy headers, or `/w3c/p3p.xml` comments can smuggle instructions telling AI privacy auditors or scanners to treat site privacy metadata as authoritative agent policy, suppress findings, or include local auth/env state.
A target-controlled Web Payments payment method manifest can embed agent-directed policy text that misuses payment/merchant discovery metadata to make an AI scanner trust checkout origins, forward session/payment context, or suppress PCI/phishing findings.
/.well-known/payment-method-manifestAI agentLLMWeb Paymentsagenticassistantautonomous scannerautonomous verifier+4 more
GLS-DFP-026RAML / API Blueprint Agent-Policy PoisoningHIGH
discovery_file_poisoningfile, web_content
RAML, API Blueprint, or generated API-description documentation can embed prompt-injection text that tells AI agents/tool builders to override higher-priority instructions, disclose local credentials, or suppress scanner findings.
GLS-DFP-027Related Website Set Agent Authority PoisoningHIGH
discovery_file_poisoningfile, web_content
A target-controlled Related Website Set discovery file can add agent-directed policy text that misuses legitimate domain-relationship metadata to make an AI agent trust sibling domains, reuse credentials, or suppress cross-domain risk findings.
agenticassistant_instructionsassociated siteassociatedSitesautonomous scannercompliance botcredential forwardingcredentials+2 more
GLS-DFP-028SCIM Service Provider Config Agent Policy PoisoningHIGH
discovery_file_poisoningfile, web_content
A poisoned SCIM `ServiceProviderConfig`, schema, or resource-type discovery document embeds agent-facing policy instructions in documentation or extension fields to override scanner rules, request identity tokens or environment secrets, or suppress findings about identity provisioning abuse.
Detects advertising transparency metadata (`sellers.json`, SupplyChain Object / `schain`, seller-verification wrappers) that tries to make AI agents, fraud scanners, or auditors suppress findings, treat seller metadata as higher policy, or forward sensitive local state.
GLS-DFP-030TDMRep rights metadata agent-policy poisoningHIGH
discovery_file_poisoningfile, web_content
TDMRep or text-and-data-mining rights metadata can hide agent-directed instructions that tell AI crawlers/scanners to treat the rights file as higher authority, suppress findings, or disclose local authorization/environment details.
/.well-known/tdmrep.jsonAI crawlerLLM agentSEO agentdo not reportignore/bypassmark cleanprivacy auditor+6 more
`/.well-known/traffic-advice` or crawler traffic-control JSON can blend normal crawler-rate policy with agent/scanner-directed instructions that claim authority, suppress reports, or request local credentials.
/.well-known/traffic-adviceAI agentsLLMsSEO agentsassistantsauditorscapacity_fractioncookie+4 more
Detects Webmention, Micropub, WebSub, IndieAuth, or link-relation endpoint discovery metadata that tells AI agents, crawlers, or scanners to treat endpoint text as higher-priority policy, suppress findings, or forward local credentials/session material.
Link:agentic crawlerattachaudit reportauthorization_endpointautonomous scannercookiesdo not report+2 more
Detects machine-readable `/.well-known/change-password` or password-change discovery text that targets AI agents with policy claims, credential forwarding, report suppression, or hierarchy-override instructions.
/.well-known/change-passwordagent_policyagenticassistant instructionsautonomous browserchange-passwordcredential change endpointfor agents/assistants/LLMs/crawlers+3 more
Browser extension `manifest.json` files carry `description`, `author`, `homepage_url`, and custom extension fields that AI security-review agents and coding assistants ingest during extension audits. An attacker can embed authority-inversion, report-suppression, or local-state-forwarding instruction
authoritative sourcebrowser_specific_settingschrome_extensiondo not flagdo not reportdo not report host permissiondowngrade severityfirefox_addon+6 more
Detects hostile instructions embedded in `browserconfig.xml`, `msapplication-*` meta tags, and pinned-site tile metadata that try to make AI agents, crawlers, or scanners treat decorative site metadata as policy, hide findings, or forward local secrets.
<browserconfig><msapplication>API tokensAuthorization headersSEO agentSafari pinned tabautonomous scanner/crawler/auditorbrowserconfig.xml+4 more
Machine-readable vulnerability-advisory metadata such as CSAF, VEX, and generated security-advisory JSON can carry agent/scanner-directed instructions that try to suppress CVE findings, downgrade exploitability, or forward local secrets during automated dependency/security review.
AI agentsCVE-YYYY-NNNNLLM agentsaggregateSeverityassistantsattachautonomous scannerscsaf+4 more
Docker Compose files support `x-*` extension fields and `labels` at service, network, volume, and top levels that carry arbitrary free-text metadata. AI DevOps agents that read Compose files during deployment planning, security review, or container lifecycle management may ingest these fields as tru
DevOps agent\bagents?\bagentsauth contextauthoritativeautonomous scannercanonical policycompose.yaml+3 more
Malicious `LABEL`, `ENV`, comment (`#`), and `ONBUILD` instructions embedded in Dockerfiles / Containerfiles can carry AI-agent/scanner-directed authority inversion, report suppression, or credential/local-state forwarding requests. AI coding agents that review Dockerfiles during security audit, bui
(?<![a-zA-Z0-9])- Hygiene report:.github/workflows/*.ymlIntake:LABELMakefileONBUILDai-agent / scanner audience+4 more
AI coding agents are trained to read `.env.example` (and `.env.template`, `.env.sample`) to understand required environment variables. A hostile `.env.example` can inject agent instructions that request credential forwarding, suppress scanner findings, or assert authority over system/developer rules
# Agent instruction:# For AI coding agents:# agent...$ANTHROPIC_API_KEY$OPENAI_API_KEY) | Handle.cursor/rules.env+6 more
An attacker embeds hostile AI-agent instructions in Helm Chart.yaml `description`, `annotations`, `maintainers`, `keywords`, `appVersion`, or `x-*` extension fields, exploiting the agent's trust in chart metadata during deployment planning, security scanning, or Kubernetes auditing to suppress findi
"1.0.0-agent-skip-checks""agent-suppress-findings""scanner-hide-csp"AI agentsAPI_KEYAutomated toolsChart.yamlDoes not override+4 more
GLS-DFP-041Hugging Face Model Card Agent Policy PoisoningHIGH
discovery_file_poisoningfile, web_content
A Hugging Face model card (README.md with YAML frontmatter) carries agent-targeted instructions — authority inversion, report suppression, or credential forwarding — that an AI agent browsing HF Hub for model evaluation will treat as trusted model-documentation policy.
---\nHugging Faceagent instructiondatasets:for agentslanguage:license:metrics:+6 more
Kubernetes annotations and labels on Deployments, Pods, Services, ConfigMaps, and CRDs carry arbitrary free-text metadata that AI DevOps agents, security scanners, and cluster-automation assistants ingest during deployment planning, compliance review, and runtime monitoring. An attacker can embed au
(?:primary|single) source of truth-instructionsConfigMapDeploymentDevOps agentSRE assistantService_instructions+1 more
AI agents that inspect container images treat OCI labels and manifest annotations as trusted context. A malicious image publisher can plant agent-directed instructions in `org.opencontainers.image.description`, custom labels, or manifest annotations that cause the agent to disable security scanners,
Chart.yamlLABELOPENAI_API_KEYai-agent audience languageai.agent.noteannotationsauditing a container image for security posturedocker inspect+5 more
`robots.txt` is the most universally consumed machine-readable policy file on the web. Attackers can embed agent-targeting instructions in comments, custom directives, `Sitemap:` pointers, and `User-agent:` sections that AI agents ingest as trusted site policy — enabling authority inversion, credent
# AI AGENTS AND SECURITY SCANNERS:*robots*AI agent(s)?Agent-policy:Crawler-note:Scanner-policy:User-agent: GPTBot
A `security.txt` file (RFC 9116) hides agent/scanner instructions in comments, extension fields, `Contact` values, or a `Policy` URL, telling AI vulnerability scanners to suppress findings, forward local credentials, or treat the metadata as authority that supersedes scanner rules.
AI agentsAPI tokenCI_ENVContact:/Expires:/Encryption:
GLS-DFP-047Sitemap XML Agent Policy PoisoningMEDIUM
discovery_file_poisoningfile, web_content
Attackers embed AI-agent/scanner-directed policy instructions (authority inversion, report suppression, credential forwarding) inside sitemap.xml XML comments, custom namespace extension elements, and `<url>` text fields, exploiting the fact that AI agents and automated scanners consume sitemaps as
<sitemapindexagent instructionattach tokensauthoritativeautonomous scannercanonical policydo not flagdo not report+1 more
A WebAuthn/passkey related-origins metadata file hides agent/scanner instructions in extension text, telling AI passkey auditors to override trusted instructions, suppress origin/RP ID mismatch findings, or include local authorization material.
/.well-known/webauthnRP IDRP ID mismatchWebAuthnagent_noteassistant_instructionsaudit_notecopy+2 more
Consent-management and cookie-preference metadata can smuggle instructions to AI privacy/compliance agents that claim cookie consent text is authoritative policy, suppress privacy findings, or forward cookies, consent strings, tokens, or local environment context.
AI agentsCMP configCookiebotDidomiIAB TCFKlaroLLMsOneTrust+6 more
Deployment-platform configuration files such as `netlify.toml`, `vercel.json`, Cloudflare `wrangler.toml`, `_headers`, and `_redirects` can carry agent/scanner-directed metadata that claims deployment config is authoritative policy, suppresses security findings, or asks agents to forward local deplo
GLS-DFP-051Documentation Site Config Metadata PoisoningHIGH
discovery_file_poisoningfile, web_content
Documentation-site configuration files such as `mkdocs.yml`, `docusaurus.config.js`, `.vitepress/config.ts`, `sidebars.js`, or Docsify config can carry agent-facing policy text that tells AI documentation/security agents to treat the config as authoritative, suppress docs/security findings, or forwa
agent instruction:agent_instructionsassistant_notecrawler_noticemkdocs.ymlnav:scanner instruction:scanner_policy+4 more
GLS-DFP-052Global Privacy Control metadata agent-policy poisoningHIGH
discovery_file_poisoningfile, web_content
A hostile site can place agent-directed authority, report-suppression, or credential-forwarding instructions in Global Privacy Control (GPC) / Sec-GPC-adjacent privacy metadata so AI privacy auditors or scanners over-trust privacy-signal text as scanner policy.
"globalPrivacyControl""gpc""gpc": true.well-known/gpc.jsonGPC headerGPC signalGlobal Privacy ControlSec-GPC+7 more
Attacker-controlled linter or formatter config metadata (`eslint.config.js`, `.eslintrc`, `.prettierrc`, `biome.json`, Stylelint config, or adjacent rule comments/custom fields) tells AI coding/security agents to treat the config as higher-priority policy, suppress findings, or forward local runtime
.eslintrc.prettierrc.stylelintrcagent instructionauthoritativebiome.jsoncanonical/definitive policyeslint.config.*+7 more
A hostile `sonar-project.properties` or SonarQube/SonarCloud configuration metadata field can target AI code-review/scanner agents with authority-inversion, report-suppression, or credential-forwarding instructions disguised as scanner policy.
AI agentsSonarCloudSonarQubeagent/scanner instructionagentsassistantsauthoritativeautomated review+7 more
GLS-DFP-055systemd Unit File Agent Policy PoisoningHIGH
discovery_file_poisoningfile, web_content
A malicious `systemd` unit file, generated `systemctl show` dump, or service/timer metadata field can target AI agents or security scanners with fake authority, report-suppression, or credential-forwarding instructions embedded in otherwise inert service configuration text.
.service.socket.timerDescription=Documentation=Environment=ExecStart=[Service]+7 more
Terraform/OpenTofu module and provider metadata can embed agent-targeted policy instructions in `description`, README-derived registry text, variable/output docs, provider schema docs, or `x-agent`-style sidecar fields that tell IaC agents to suppress drift/security findings or forward local Terrafo
.tfstate.tfvarsAI agentsDevOps agentsIaC agentsLLMsOpenTofuagent/scanner instructions+7 more
GLS-DFP-057OPA/Rego policy metadata poisoningHIGH
discovery_file_poisoningfile, web_content
OPA/Rego policy files and policy-bundle metadata can carry agent-directed instructions that tell AI security/review agents to treat policy comments, package metadata, ConstraintTemplate descriptions, or Conftest output as higher-priority review policy, suppress findings, or forward runtime/context m
.manifest.regoAI agentsConstraintTemplateGatekeeperIaC scannersagent instructionagent_instructions+6 more
GLS-DFP-058Allure report metadata poisoningHIGH
discovery_file_poisoningfile, web_content
Allure test-report JSON, widget, executor, environment, attachment-name, or rendered report metadata can carry agent-directed instructions that make CI/review agents suppress findings, rewrite test verdicts, or forward CI/runtime context.
AI agentsallure-results/*.jsoncategories.jsoncontainer.jsondo not obey/treat/use Allure metadataenvironment.propertiesexecutor.jsonfor agents+3 more
Generated API portal/catalog metadata (Stoplight, ReadMe, Redocly, developer portals, endpoint catalogs) can carry agent/scanner-directed authority inversion, report suppression, or credential/local-state forwarding instructions in documentation strings that AI API agents ingest as trusted reference
Archive-level comments, TAR/PAX headers, xattrs, or listing-tool metadata can carry agent/scanner-directed policy text that tells AI artifact reviewers to suppress findings or forward local scan context.
7z commentAI agentsPAXHeaderagentsarchive metadataartifact auditorsartifact bundleassistant+7 more
GLS-DFP-062Autotools Build Metadata PoisoningHIGH
discovery_file_poisoningfile, web_content
Attacker-controlled Autotools build descriptor text (`configure.ac`, `Makefile.am`, `m4/*.m4`, `aclocal.m4`, generated configure help) can smuggle agent/scanner-directed policy claims that suppress findings or request local build/runtime context.
--helpAI agentsMakefile.amaclocal.m4agent_instructionsauditor notesautomated build reviewconfig.h.in+5 more
Backstage `catalog-info.yaml` and generated software-catalog entity metadata can smuggle agent/scanner-facing policy text that tells AI platform or security agents to treat catalog descriptors as authoritative, suppress service findings, or forward runtime/CI context.
agent_policyapiVersion: backstage.io/assistant_notecatalog-info.yamlcatalog-info.ymlconsumesApisdo/does notmetadata.annotations+7 more
GLS-DFP-065Bunfig / Bun runtime config metadata poisoningHIGH
discovery_file_poisoningfile, web_content
Attacker-controlled Bun configuration or lock/runtime metadata (`bunfig.toml`, `bun.lock`, `bun.lockb`, package-manager Bun fields, registry/install notes) can tell AI dependency/security agents to treat the metadata as higher-priority policy, suppress audit findings, or forward local registry/runti
bun installbun.lockbun.lockbbunfig.tomlinstall.scopespackageManager: buntrustedDependencies
Attacker-controlled coverage-service configuration (`codecov.yml`, `.codecov.yml`, `.coveralls.yml`, Coveralls/Codecov YAML comments or custom fields) can smuggle agent-facing policy that tells AI CI/review agents to suppress coverage/security findings or forward CI/runtime context.
Commitlint configuration files can smuggle agent-facing commit/release-review instructions that claim authority over scanners, suppress commit-policy or supply-chain findings, or solicit local git/CI credentials from AI coding and release agents.
.commitlintrc*@commitlint/*commitlintcommitlint.config.*formattergoverning policyignorespackage.json+3 more
GLS-DFP-071Feature Flag Configuration Metadata PoisoningHIGH
discovery_file_poisoningfile, web_content
Feature-flag and experimentation metadata can smuggle agent-directed authority, report-suppression, or local-state forwarding instructions into files AI release, QA, and security agents already treat as operational context.
`.git-blame-ignore-revs` files control which commits `git blame` skips. Attackers embed agent-targeting instructions in `#` comment lines alongside real formatting SHAs, poisoning both the blame-exclusion list and agent review behavior through a single file.
**N2 — Normal git documentation****N3 — Scanner documentation****N4 — Security training example****N5 — Defensive denial****N6 — Normal comment + SHAs****N7 — Benign policy explanation**--ignore-revs-file.git-blame-ignore-revs+7 more
GLS-DFP-073GitHub Action metadata poisoningHIGH
discovery_file_poisoningfile, web_content
A malicious reusable GitHub Action can hide agent/scanner-directed instructions in `action.yml` / `action.yaml` metadata fields so AI coding, CI-review, or supply-chain agents treat Marketplace/action descriptor text as policy, suppress findings, or forward local CI/runtime credentials.
GITHUB_TOKENGitHub Action metadataaction.yamlaction.ymlagent instructionsattachbrandingcanonical+7 more
Browser HAR files, proxy captures, and DevTools network exports can carry agent/scanner-directed instructions in comments, custom fields, response headers, or captured bodies that tell AI auditors to treat the capture as policy, suppress findings, or forward local auth/runtime material.
.harAuthorizationChrome DevTools network exportFirefox Network MonitorHAR 1.2HTTP ArchiveSet-Cookieagent_policy+7 more
Heroku/Dokku `app.json` deployment manifests can carry agent/scanner-directed policy text in descriptions, env-var metadata, scripts, or custom fields that tells AI deployment agents to treat the manifest as authoritative, suppress findings, or forward local/platform credentials.
addonsagent_policyapp.jsonassistant_notebuildpacksdescriptiondo/does notenv+7 more
GLS-DFP-077JetBrains Run Configuration Metadata PoisoningHIGH
discovery_file_poisoningfile, web_content
JetBrains IDE run/debug configuration XML can carry agent/scanner-directed authority inversion, report suppression, or local-state forwarding instructions that AI coding/debugging agents may mistake for project execution policy.
.idea/runConfigurations.iws<configuration><option name=...>RunManagerconfiguration@nameoption@nameoption@value+2 more
Lighthouse, PageSpeed, WebPageTest, Core Web Vitals, or performance-budget report text can carry agent-directed policy, suppression, or credential-forwarding instructions that downstream AI web/release/security agents may mistake for trusted review guidance.
MIME `Content-Disposition` / attachment filename metadata can carry agent-directed policy, suppression, or credential-forwarding instructions that downstream AI mail, ticket, or security agents may mistake for trusted review guidance.
Mutation-testing reports and their generated HTML/JSON/log metadata can carry agent-directed policy text that asks AI review or CI agents to override mutation thresholds, suppress surviving-mutant findings, or forward runtime/local state.
Attacker-controlled Playwright report artifacts (`playwright-report`, `trace.zip`, screenshots, videos, stdout/stderr attachments, and HTML/blob reports) can smuggle agent-directed instructions into test evidence, causing AI coding or QA agents to suppress findings, trust forged test policy, or forw
AI test agentsAllure PlaywrightLLM reviewersPlaywrightagent instructionsassistant directiveauthoritative QA policyautonomous QA scanners+7 more
Python linter and type-checker configs can carry agent-directed comments or custom fields that tell AI coding/security agents to treat the config as review policy, suppress findings, or forward local context.
.flake8.pylintrc[mypy][pylint]agent_instructionsfindings should be suppressedmypy.inipyrightconfig.json+5 more
GLS-DFP-083Redacted HAR Bundle Sidecar PoisoningHIGH
discovery_file_poisoningfile, web_content
Redacted HAR/debug bundles can hide agent-directed instructions in adjacent redaction or replay sidecars, causing AI support/security agents to suppress auth/session findings or forward local replay/runtime context even when the HAR itself is benign.
.harHAR bundleREADME-support-bundle.mdagent_policyassistant_notecapture.hardebug bundlenetwork capture bundle+7 more
Attacker-controlled Release Please or Changesets configuration text can smuggle agent/scanner instructions that redefine release-review authority, suppress dependency/release findings, or solicit CI/npm/GitHub credentials from AI release agents.
WebdriverIO / Selenium test configuration fields and comments can smuggle agent-facing instructions that tell QA/security agents to treat test-runner metadata as authoritative, suppress browser/test findings, or forward runtime/session state.
Attacker-controlled WebGPU/WebGL shader source comments, shader metadata, or shader compiler-output notes carry instructions to AI code/security agents to suppress shader findings or forward local/browser/runtime secrets.
agent_policydo not obeyno agent instructions presentno policy overridesscanner_policyshould report
GLS-DFP-089OpenTelemetry trace and baggage metadata poisoningHIGH
discovery_file_poisoningfile, web_content
Attacker-controlled OpenTelemetry span/resource/log attributes, `baggage`, or `tracestate` values can carry agent-facing policy instructions that an AI incident-response or security agent may mistake for trusted triage guidance.
AI agentsOTLPOTelOpenTelemetrySRE botsagent_policyautomated incident triagebaggage+7 more
PowerShell module manifests (`.psd1`) and adjacent module metadata fields can smuggle agent/scanner-directed policy text that tells AI dependency or security agents to suppress findings or forward local secrets.
.psd1FunctionsToExportModuleVersionNew-ModuleManifestPrivateData.PSDataReleaseNotesRootModuleagent_policy+6 more
Repository-controlled GitHub Discussion templates or discussion-form YAML fields carry agent-facing instructions that try to turn community routing copy into scanner/reviewer policy.
.github/DISCUSSION_TEMPLATEAI agentsDISCUSSION_TEMPLATEagent instructionagentsassistant policyassistantsauditors+7 more
Repository ruleset or branch-protection exports can smuggle agent-directed policy text that tells AI release/security agents to treat platform governance metadata as higher authority, suppress branch-protection findings, or forward local GitHub/CI context.
AI agentsagent_review_policyassistant policybranch protectionbranch_protectionbypass_actorscompliance auditorsrelease agents+7 more
DNS SRV/TXT Service-Discovery Agent-Policy Injection: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — dNS SRV/NAPTR records, distinct from existing SVCB/HTTPS patterns.
Oauth Dynamic Client Registration Metadata Prompt Smuggling: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — oAuth registration metadata fields specifically, distinct from consent or resource metadata.
Copilot Instruction-File Frontmatter Suppression: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — explicit agent instruction files (.instructions.md) rather than generic metadata descriptors.
Thrift IDL Docblock Directive Poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — specific to Thrift IDL files, not covered by existing file-type patterns.
AGENTS.md Setup-Checklist Installer Lure: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — binary execution social engineering in docs, distinct from build metadata.
Avro Schema Registry Metadata Poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — targets Avro schema and registry metadata poisoning specifically.
Conda environment.yml metadata poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — conda-specific metadata and fields not covered by existing config-poisoning patterns.
Cypress E2E Config Metadata Poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — targets Cypress E2E test configuration metadata poisoning specifically.
HTTP Cache-Metadata Policy-Source Poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — targets HTTP caching protocol metadata and proofs as policy sources.
GLS-DFP-093Checkstyle XML Error-Message Suppression DirectiveHIGH
discovery_file_poisoningfile, api_response
Checkstyle XML Error-Message Suppression Directive: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — xML static analysis report formats (Checkstyle/PMD/SpotBugs), not covered by existing patterns.
GLS-DFP-094Data URI SVG metadata prompt smugglingHIGH
discovery_file_poisoningfile, api_response
Data URI SVG metadata prompt smuggling: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — data URI transport specifically; existing SVG patterns are bound to BIMI discovery.
MIME Quoted-Printable Encoded Instruction Smuggling: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — encoding-based bypasses (Quoted-Printable soft breaks) for instruction smuggling.
MCP Setup Doc Bootstrap-Bundle Lure: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — repository onboarding/bootstrap social engineering for binary execution.
ERC-4337 UserOperation Paymaster Approval Suppression: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — addresses Account Abstraction (ERC-4337) and Paymaster metadata poisoning.
WalletConnect appMetadata Signing-Approval Suppression: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — dApp and Web3 wallet manifest metadata, a unique attack surface.
Hardware-Wallet Ledger Policy Approval Suppression: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — hardware wallet (Ledger/Trezor) and blind signing metadata poisoning.
Semgrep Results Finding-Suppression Directive: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — semgrep-specific finding metadata not covered by generic SARIF or config patterns.
WalletConnect grantPermissions Session-Key Authority Poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — wallet permission metadata and authority inversion in transaction previews.
Wallet Preview Linked Dashboard Prompt Poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — wallet-specific simulation dashboard links, distinct from general API portal metadata.
Blockchain Transaction Simulation Trace Poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — blockchain transaction simulation and trace metadata for authority inversion attacks.
EIP-712 Typed-Data Signing Authority Inversion: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — eIP-712 typed-data signing metadata and permit-based authority inversion.
WalletConnect Session-Proposal Namespace Poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — walletConnect session proposal and namespace metadata used to deceive wallet agents.
WalletConnect Session-Request Event Poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — walletConnect session request and event metadata for deceiving transaction agents.
Task-Queue / Kanban Worker-Authority Poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — internal task-queue and Kanban metadata for worker-agent authority inversion.
Web3 SIWE / CAIP-122 Auth-Challenge Poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — web3/Wallet auth challenges (SIWE/SIWS/CAIP-122) not handled by general auth patterns.
CTest / Dart Log-Artifact Poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — cTest/Dart log artifacts; distinct from CMake config poisoning in GLS-BMP-004.
GLS-DFP-119Go test2json Output PoisoningHIGH
discovery_file_poisoningfile, api_response
Go test2json Output Poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — go test JSON output format (test2json), distinct from general logs.
GLS-DFP-121Jest JSON Test-Result PoisoningHIGH
discovery_file_poisoningfile, api_response
Jest JSON Test-Result Poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — jest JSON test results, distinct from general test metadata or logs.
JSON Schema `$comment` / annotation instruction smuggling: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — jSON Schema is a distinct format critical for structured LLM tool-calling contexts.
Web3 Wallet Signing-Queue Approval-Graph Poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — web3 wallet signing queues and approval graphs not covered elsewhere.
GLS-DFP-126Wallet Deep-Link URI Parameter ShadowingHIGH
discovery_file_poisoningfile, api_response
Wallet Deep-Link URI Parameter Shadowing: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — wallet deep-link/URI parameter shadowing and homoglyph attacks.
Payment-Request / Invoice Instruction Smuggling: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — malicious instructions within payment requests, invoices, and checkout metadata.
Wallet Transaction-Simulation Preview Poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — poisoning of wallet transaction simulations and decoded preview metadata.
GLS-DFP-129Wallet Qr Scan Label Instruction SmugglingHIGH
discovery_file_poisoningfile, api_response
Wallet Qr Scan Label Instruction Smuggling: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — unique mechanism targeting QR code scanning and decoded labels in wallet contexts.
Wallet Preview Safe-Verdict Injection: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — direct injection of safe security verdicts/scores into wallet preview metadata.
SIWE Wallet-Authentication Instruction Smuggling: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — malicious instructions within SIWE and wallet authentication messages.
GitHub Merge-Queue Metadata Poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — gitHub Merge Queue and Merge Group metadata poisoning specifically.
GitLab CodeClimate Quality-Report Poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — gitLab/CodeClimate code quality report metadata specifically, not covered by existing patterns.
JSON-RPC Batch Response-Order Poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — jSON-RPC batch response ID/order poisoning, distinct from static API metadata poisoning.
pytest-json-report Metadata Poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — pytest-json-report specific metadata schemas, distinct from Allure or mutation reports.
Wallet Deeplink Decoder Prompt Reassembly: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — reassembly of fragmented/encoded deep-link parameters during wallet signing flows.
Account-abstraction paymaster / bundler reputation poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — new vector for Web3/ERC-4337 account abstraction metadata and reputation fields.
GLS-DFP-147Card: Outbox Handoff SuppressionHIGH
discovery_file_poisoningfile, api_response
Card: Outbox Handoff Suppression: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — specific outbox/handoff suppression logic in workflow artifacts, distinct from listed patterns.
GLS-DFP-139JUnit XML system-out/system-err tool-output poisoningHIGH
discovery_file_poisoningfile, api_response
JUnit XML system-out/system-err tool-output poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — standard test report format not covered by existing XML or tool-output patterns.
GLS-DFP-140JUnit XML system-output base64 rehydration prompt smugglingHIGH
discovery_file_poisoningfile, api_response
JUnit XML system-output base64 rehydration prompt smuggling: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — structural targeting of JUnit XML output combined with base64 rehydration instructions.
GLS-DFP-141Prettier config metadata poisoningHIGH
discovery_file_poisoningfile, api_response
Prettier config metadata poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — common dev tool config not covered by existing lint/CI config patterns.
Readme Encoded Source Archive Helper Lure: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — doc-based lures for fetching and executing malicious encoded archives.
Stylelint config metadata poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — stylelint-specific filenames and keywords not covered by existing linter patterns.
GLS-DFP-144Wallet Payment Uri Parameter ShadowingHIGH
discovery_file_poisoningfile, api_response
Wallet Payment Uri Parameter Shadowing: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — unique mechanism targeting blockchain payment URI parameter shadowing to hide risks.
Wallet Visual Risk Badge Prompt Poisoning: a carrier-native prompt-injection that embeds authoritative suppression / authority-inversion instructions an AI agent may obey — visual/OCR-based wallet risk indicators, distinct from repository status badges.
Sunglasses can measure traffic and campaign performance, but only if you say yes. Essential storage stays on. Analytics and marketing stay off until you choose.
We are not doing the fake "trust us" banner. The site works without analytics. If you opt in, Sunglasses will use analytics and marketing storage to measure what pages work and which campaigns bring real buyers back. If you say no, non-essential Google consent stays denied.
Essential
Required to remember this choice and keep core site behavior stable.