Skip to content

feat(dev-hooks): flag hidden Unicode-steganography prompt injection on Read - #28

Closed
mickzijdel wants to merge 1 commit into
mainfrom
feat/hidden-text-injection-hook
Closed

mickzijdel wants to merge 1 commit into
mainfrom
feat/hidden-text-injection-hook

Conversation

@mickzijdel

Copy link
Copy Markdown
Owner

Summary

commit-digest Run 21 own idea. nateberkopec/dotfiles had no new commits since Run 20 (HEAD is still 5d5ca95); the ai-productivity-digest feed's "beware hidden prompt-injection text (e.g. white 3pt font)" item (source) prompted this, but scoped down to a reliable signal rather than the fuzzier one the feed item described:

  • New PostToolUse(Read) hook (hidden-text-reminder.sh): scans a file Claude just read for Unicode steganography used to smuggle invisible instructions past a human reviewer while an LLM still parses them — Unicode Tag characters (U+E0000–U+E007F, the "ASCII smuggling" range) or a run of 6+ zero-width characters (U+200B/U+200C/U+200D/U+2060/U+FEFF). On a hit it feeds a correction back (exit 2, every occurrence — no fire-once, since each file could carry different hidden content) telling Claude to inspect the flagged region before treating it as instructions.
  • Deliberately doesn't attempt the CSS-visibility heuristic (font-size:0, color-on-color, display:none) from the original tip — that needs style computation this hook can't do reliably from raw bytes, and false-positiving on legitimate small/hidden UI markup wasn't worth it. The Unicode-based signals have essentially no legitimate use in real documents, so it stays silent on ordinary files.
  • Registered in hooks.json as a new PostToolUse → Read matcher (first hook on that event/tool combo).
  • README (plugin + root) and plugin.json updated; version bumped 2.32.2 → 2.33.0 (new hook = minor).

Test plan

  • uv run pytest -q — 621 passed (8 new tests: fires on Unicode Tag chars, fires on a zero-width run, silent on plain text/binary/missing files, silent below the 6-char zero-width threshold, opt-out honored, fires on every occurrence with no fire-once suppression)
  • shellcheck — clean
  • shfmt -d — no diff
  • bash scripts/run-jscpd.sh python,bash — 0 clones
  • claude plugin validate --strict on the marketplace and the dev-hooks plugin — both pass
  • Manually verified the hook against a normal file (silent), a zero-width-steganography fixture, and a Unicode-tag-steganography fixture

Generated by Claude Code

…n Read

commit-digest: dotfiles had no new commits since Run 20; own idea prompted
by the ai-productivity-digest feed's "beware hidden prompt-injection text"
item — scope it to a reliable signal (Unicode Tag chars / zero-width runs)
rather than the fuzzier CSS-visibility heuristic the feed item described.

New PostToolUse(Read) hook scans file content for Unicode Tag characters
(U+E0000-U+E007F, the ASCII-smuggling range) or a run of 6+ zero-width
characters, and feeds a correction back so Claude inspects suspicious
content before treating it as instructions.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DZdo4fGEBQEtC1pr3CKEKC
@mickzijdel mickzijdel closed this Sep 24, 2026
@mickzijdel
mickzijdel deleted the feat/hidden-text-injection-hook branch September 24, 2026 05:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants