Malicious AI instruction files threaten agentic workflows
🛡️ Security researchers warn that shared AI agent instruction files and configuration artifacts can be weaponized to exfiltrate prompts, environment variables, and credentials. Examples include poisoned CLAUDE.md, .cursorrules, GEMINI.md and JSON config files that instruct agents to silently send sensitive data to cloud sinks like Supabase or Webhook.site. The technique, dubbed “PromptLogger,” evades traditional EDR detection since the agent itself performs the exfiltration, and repositories with such poisoned files have been observed on GitHub.
