← Back to feed
AI SecurityEmerging1 sourceAug 23, 2025 · 23:20via Embrace The Red (AI agent security)

Sneaking Invisible Instructions by Developers in Windsurf

Brief

Imagine a malicious instruction hidden in plain sight, invisible to you but not to the AI. This is a vulnerability discovered in Windsurf Cascade, it follows invisible instructions. This means there can be instructions in a file or result of a tool call that the developer cannot see, but the LLM does.

Some LLMs interpret invisible Unicode Tag characters as instructions, which can lead to hidden prompt injection.

Read more on Embrace The Red (AI agent security)