Study Finds Repo Scanners Miss All Agent-Directed Prompt Injection Payloads

A benchmark study published in September 2025 tested how well common repository security scanners and a specialist agent-facing detector identify hostile payloads embedded in code repositories. The test corpus included 192 files — 118 carrying agent-directed hostile payloads and 72 clean controls — scanned by gitleaks, semgrep, and Sentinel InjectionGate. Neither gitleaks nor semgrep flagged any of the 118 agent-directed payloads, as both tools are designed for secrets detection and static code analysis respectively, not for identifying natural-language instructions targeting AI agents. Sentinel InjectionGate, purpose-built for agent-facing threats, was evaluated separately to identify which payload classes it detected and which it missed. The study emphasizes that the gap reflects a difference in design scope rather than product failure, and does not claim any vendor tool is vulnerable or that detection guarantees safe handling.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.



Discussion (0)
Log in to join the discussion and vote.
Log in