IH-INJ-002highPrompt injection

Hidden content

Invisible characters, HTML comments, and huge base64 blobs can hide instructions from a person reading the file.

What does IH-INJ-002 flag?

Flags content that a person reading the file would not see: invisible Unicode characters, HTML comments with instruction-like words, and very long base64 blobs.

  • Zero-width characters (U+200B, U+200C, U+200D, U+2060, U+FEFF), bidirectional controls (U+202A to U+202E and U+2066 to U+2069) and Unicode tag characters.
  • HTML comments of up to 4,000 characters that contain ignore, instruction, system prompt, do not tell or secret.
  • A base64-like run of 200 to 2,000 characters on one line, reported with medium confidence.

Why it matters

Hidden text lets a skill show a reviewer one thing and the agent another. Invisible Unicode and smuggled instructions are documented prompt-injection techniques against agent skills.

Examples

Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.

Instruction in a comment
Flagged
<!-- system prompt: … -->
Short base64 token
Not flagged
A short token aGVsbG8=

Can IH-INJ-002 fire on a safe skill?

  • Emoji sequences and some writing systems use zero-width joiners legitimately.
  • Images or fonts embedded as base64 data.
  • Editor comments that happen to say “instruction”.

How do I fix an IH-INJ-002 finding?

  • Remove hidden characters and comments.
  • Keep data files separate from the skill instructions.

How do I tune or allow IH-INJ-002?

For a data file that legitimately contains base64, keep it outside the instructions and exclude it with ignoreGlobs.

{
  "ignoreGlobs": [
    "docs/known-example.md"
  ]
}

Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-INJ-002.

What can IH-INJ-002 miss?

  • Base64 shorter than 200 characters. The encoded one-liners in reported campaigns were shorter than that; IH-EXEC-001 catches them when they are piped into a shell on the same line.
  • Text hidden by other means, such as styling, images or other file formats.
  • Look-alike letters and Unicode tricks outside the listed ranges.

No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.

Scores and thresholds shown are the CLI defaults; your config can change them. List every rule from the terminal with ironheights rules list.

All 35 rules