Coding assistants follow project-level instruction files to match team conventions. Because these files are trusted and rarely reviewed closely, they offer a stealthy place to plant instructions.
Rules file backdoor techniques include:
Once committed, a poisoned rules file affects every developer and agent working in the repository, turning a single change into a persistent supply chain compromise.
Defenses include treating agent instruction files as code subject to review, scanning them for hidden characters and suspicious directives, and monitoring what coding agents generate and execute.
How PointGuard AI Helps
PointGuard AI Agentic Endpoint Security monitors coding agents and the configuration they load on developer machines, and AI Runtime Guardrails detect hidden instructions and invisible Unicode in content agents process.
Learn More
Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.