What does IH-INJ-002 flag?
Flags content that a person reading the file would not see: invisible Unicode characters, HTML comments with instruction-like words, and very long base64 blobs.
- Zero-width characters (U+200B, U+200C, U+200D, U+2060, U+FEFF), bidirectional controls (U+202A to U+202E and U+2066 to U+2069) and Unicode tag characters.
- HTML comments of up to 4,000 characters that contain ignore, instruction, system prompt, do not tell or secret.
- A base64-like run of 200 to 2,000 characters on one line, reported with medium confidence.
Why it matters
Hidden text lets a skill show a reviewer one thing and the agent another. Invisible Unicode and smuggled instructions are documented prompt-injection techniques against agent skills.
Examples
Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.
Can IH-INJ-002 fire on a safe skill?
- Emoji sequences and some writing systems use zero-width joiners legitimately.
- Images or fonts embedded as base64 data.
- Editor comments that happen to say “instruction”.
How do I fix an IH-INJ-002 finding?
- Remove hidden characters and comments.
- Keep data files separate from the skill instructions.
How do I tune or allow IH-INJ-002?
For a data file that legitimately contains base64, keep it outside the instructions and exclude it with ignoreGlobs.
Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-INJ-002.
What can IH-INJ-002 miss?
- Base64 shorter than 200 characters. The encoded one-liners in reported campaigns were shorter than that; IH-EXEC-001 catches them when they are piped into a shell on the same line.
- Text hidden by other means, such as styling, images or other file formats.
- Look-alike letters and Unicode tricks outside the listed ranges.
No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.
Related rules
ironheights rules list.