Invisible-Instruction Smuggling Is Rare in the Wild: An Open Audit of 3,168 Public AI-Agent Extension Files
Yurtsevenler, Fevzi Ege · Zenodo (CERN European Organization for Nuclear Research) · 2026
Self-deposited technical report — not peer-reviewed. Across 3,168 public agent-extension files harvested from 2,965 unique GitHub repositories, invisible-instruction smuggling — the attack class most amplified in recent AI-agent security commentary — appears in effectively zero files. We found 0 Unicode Tags-block payloads (U+E0000–E007F), 0 bidirectional / Trojan-Source overrides, 0 variation-selector channels, and only 2 files containing zero-width characters, both of which were benign documentation. In contrast, 576 files (18.2%) carried at least one finding. The high-severity population (462 files) was driven not by smuggled instructions but by ordinary credential and secret references: scanner rule UC301 fired in 268 files, UC302 in 237, and UC403 in 134. In other words, the dominant real-world signal on this public surface is secret-handling hygiene, not covert Unicode payloads. We release the full per-file manifest and findings as an open dataset, and the scanner (uncloak) as open source, so the measurement can be re-run, disputed, or extended. This report is deliberately framed as an open, reproducible counterpart to closed vendor threat reports. We stress the honest reading: the corpus is a convenience sample from GitHub code search at a single 2026-07-26 snapshot, so absence of smuggling in this sample is not evidence of absence everywhere — it is one calibrated data point against a fear that is often asserted without measurement. Türkçe özet: 2.965 GitHub deposundan toplanan 3.168 açık ajan-uzantısı dosyası (Skill, kural dosyası, MCP yapılandırması) tarandı. Son dönemde en çok abartılan saldırı sınıfı olan görünmez-talimat kaçakçılığı bu örneklemde pratikte hiç görülmedi: 0 Unicode Tags bloğu yükü, 0 bidi/Trojan-Source çevirmesi, 0 varyasyon-seçici kanalı ve yalnızca 2 dosyada sıfır-genişlik karakteri (ikisi de zararsız belge). Buna karşılık 576 dosya (%18,2) en az bir bulgu içeriyordu; yüksek önem taşıyan 462 dosya ise gizli talimat değil, sıradan kimlik-bilgisi/sır referanslarıydı (UC301: 268, UC302: 237, UC403: 134 dosya). Yani halka açık bu yüzeydeki asıl sinyal sır-yönetimi hijyenidir. Tüm veri ve tarayıcı açık kaynak yayımlanır; bu örneklemde yokluk, her yerde yokluk anlamına gelmez. Open data & code: GitHub (code & data, open) · Hugging Face dataset · companion article: altaysec.com.tr. Author: Fevzi Ege Yurtsevenler, AltaySec (Türkiye). License: CC BY 4.0.