Google Antigravity IDE Prompt Injection

Google's Antigravity agentic IDE was designed to assist developers with file operations and code navigation. The find_by_name tool's insufficient input sanitisation allowed code execution via prompt injection; Google patched the flaw on April 21, 2026, the same day it was reported. The patch arrived the same day; the input validation did not.

Severity: Unrated · Category: Prompt Injection

Impact: Code execution via prompt injection in an agentic IDE

Source: The Hacker News · Apr 21 2026

How Fencio prevents this

The agent could not tell the difference between text it was reading and instructions it should follow. Once untrusted content reached its context window, it carried the same weight as the operator's own prompt, and the agent acted on it with every permission it had.

Fencio tags every span of context with where it came from. Instructions that arrive inside retrieved documents, tickets, emails, or tool output are treated as data, and any tool call they try to trigger is checked against the policy for untrusted content before it runs.

All incidents