TL;DR: A prompt injection in Google’s Antigravity agentic IDE can turn the find_by_name tool’s Pattern parameter into arbitrary code execution by injecting fd flags, bypassing Secure Mode because the call is treated as a native tool invocation, according to Pillar Security researchers. The deeper issue is that shell-facing parameters in agentic tools create execution paths that security boundaries may never see, so sanitisation alone is not enough.
Editorial analysis by NHI Mgmt Group, based on content published by Pillar Security: “Prompt Injection leads to RCE and Sandbox Escape in Antigravity”.
Key questions
Q: What breaks when an agentic IDE treats search input as a command-line flag?
A: The search path stops being a lookup function and becomes an execution primitive.
Q: Why do sandbox controls fail against native tool abuse?
A: Sandboxing often protects shell commands after dispatch, but native tool calls may execute earlier in the agent’s flow.
Q: What signs indicate an agent workflow can be turned into code execution?
A: Look for tool parameters that accept free-form strings, operations that can stage files and then search or transform them, and any path where attacker-controlled content can influence a subsequent tool call.
Practitioner guidance
- Harden native tool parameters Validate every parameter that can reach an underlying utility, and reject values that can be reinterpreted as flags or executables.
- Separate ingestion from execution Keep untrusted project content, file staging, and command-capable agent actions in distinct trust zones so content cannot directly trigger execution paths.
- Audit sandbox enforcement points Verify that security controls apply before the first native tool handoff, not only after shell commands are already in flight.
Bottom line: This incident shows that agentic IDEs can convert a harmless-looking file search into arbitrary code execution when native tool parameters are not strictly constrained.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Native tool parameters have become an execution boundary, not an input field. This finding shows that agentic IDEs can turn seemingly harmless search parameters into code execution paths when the parameter reaches a shell-backed utility unfiltered. The governance failure is not just missing sanitisation, but treating native tools as if they were outside the privilege model. Practitioners should classify every tool parameter that can reach a command interpreter as a high-risk control surface.
A few things that frame the scale:
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation, according to AI Agents: The New Attack Surface report.
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.
A question worth separating out:
Q: Who is accountable when an agentic IDE turns search into execution?
A: Accountability sits with the product owner, platform security team, and the governing identity programme together. If the agent is allowed to operate under delegated user authority, then the surrounding controls must be designed for that authority, including parameter validation, sandbox scope, and approval boundaries.
👉 Read our full editorial: Prompt injection in Antigravity turns file search into RCE
Native tool parameters are the new execution boundary in agentic IDEs: The security problem is no longer confined to shells, terminals, or explicit command runners. When a parameter can be reinterpreted by an underlying utility, the tool itself becomes the boundary that must be governed. For practitioners, that means execution control has to begin at input handling, not after the agent has already decided to act.
A few things that frame the scale:
- 59% of compromised machines in a major 2025 supply chain attack were CI/CD runners rather than personal workstations, according to the State of Secrets Sprawl 2026.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: How should teams govern prompt injection risk in agentic IDEs?
A: Teams should govern prompt injection as a delegated execution problem, not just a content-safety problem. The right response is to control which untrusted inputs can influence tool use, isolate file handling from execution-capable actions, and require tests that prove the agent cannot convert ordinary workspace tasks into code execution.
👉 Read our full editorial: Prompt injection in Antigravity turns file search into RCE