Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Gemini CLI Prompt Injection Flaw 2025: How a…
Breach analysis Incident: 28 Jul 2025

Gemini CLI Prompt Injection Flaw 2025: How a Poisoned README Could Make an AI Coding Agent Leak Developer Secrets

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 7 min read
Category: NHI AI agents
Attack route: Prompt injection Identities: AI agent Secret or password
On this page

Two days after Google released Gemini CLI, its command-line AI coding assistant, on 25 June 2025, researchers at security firm Tracebit found a way to make it run hidden commands on a developer's machine. Gemini CLI reads project files such as README.md and GEMINI.md into its context, and it can run shell commands, either after asking the user or automatically if the command is on the user's allow-list. Tracebit hid instructions in a README that told Gemini to run what looked like an allowed grep command, followed by a semicolon and a second command that sent all of the user's environment variables, which may contain secrets, to a remote server. Because the command started with grep, Gemini treated the whole string as allowed and ran it without asking, and whitespace could hide the malicious part from view. Tracebit reported the flaw on 27 June, and Google fixed it in version 0.1.14 on 25 July. No exploitation in the wild was reported.

Key takeaways

  • Instructions hidden in a repository's README could make Gemini CLI run commands the user had not approved.
  • Weak allow-list matching treated a grep command followed by a semicolon and a second command as plain grep, and ran it without prompting.
  • Tracebit's proof of concept silently sent the developer's environment variables, which may contain secrets, to a remote server.
  • Google fixed the issue in Gemini CLI 0.1.14 on 25 July 2025; no attacks in the wild were reported.
  • The identity lesson: an AI coding agent acts with the developer's own credentials, so untrusted content it reads can steer those credentials.

At a glance

OrganisationsGoogle (Gemini CLI); developers using Gemini CLI before version 0.1.14
WhenReported to Google 27 June 2025; fixed in 0.1.14 on 25 July 2025; disclosed 28 July 2025
AttackerNone known. Found by Tracebit
Entry pointPrompt injection through context files such as README.md or GEMINI.md in a code repository
Identities abusedThe AI agent's ability to run shell commands as the developer; secrets in the developer's environment variables (in the proof of concept)
ImpactSilent command execution and secret exfiltration demonstrated; no exploitation reported
CategoryNHI, Agentic AI and AI agents. Incident class: vulnerability found by researchers (vulnerability, no confirmed breach)

What happened

Gemini CLI loads project files into its prompt "to aid in understanding a codebase," BleepingComputer explained, and "can make recommendations, write code, and even execute commands locally, either by prompting the user first or by using an allow-list mechanism." Tracebit started testing it immediately after release and found that "it's possible to hide malicious instructions in these files to perform prompt injection, while poor command parsing and allow-list handling leave room for malicious code execution."

In its demonstration, Tracebit set up a repository with a harmless Python script and a poisoned README.md, then asked Gemini CLI to look at it. Gemini was instructed first to run grep ^Setup README.md, a benign command, and then a string that began with grep but continued after a semicolon with an exfiltration command. "For the purposes of comparison to the whitelist, Gemini would consider this to be a 'grep' command, and execute it without asking the user again," Tracebit wrote. "In reality, this is a grep command followed by a command to silently exfiltrate all the user's environment variables (possibly containing secrets) to a remote server." Tracebit added: "The malicious command could be anything (installing a remote shell, deleting files, etc)." Output could also be padded with whitespace so the user would not see the malicious part.

The attack required the user to have allow-listed a command such as grep, but BleepingComputer noted that persistent attackers could meet that condition in many cases. Tracebit said it tested the same technique against OpenAI Codex and Anthropic's Claude and found them not exploitable because of more robust allow-listing. Google fixed the issue in Gemini CLI 0.1.14.

Timeline

DateEvent
25 June 2025Google releases Gemini CLI.
27 June 2025Tracebit reports the vulnerability to Google.
25 July 2025Google releases Gemini CLI 0.1.14 with a fix.
28 July 2025The vulnerability is publicly disclosed and reported.

How it happened: the identity attack path

  1. Untrusted content read. The developer points Gemini CLI at a repository containing a poisoned README.
  2. Prompt injection. Hidden instructions tell the agent to run a crafted command.
  3. Allow-list bypass. The command starts with an allowed program, so it runs without confirmation.
  4. Secrets exfiltrated. The appended command sends environment variables, including any secrets, to a remote server.
  5. Concealment. Whitespace hides the malicious part from the user's view.

Impact

  • Demonstrated: silent execution of arbitrary commands and exfiltration of environment variables from a developer's machine.
  • Affected: Gemini CLI versions before 0.1.14.
  • Exploitation: none reported.

What this means for NHI governance

An AI coding agent is a non-human identity that borrows the developer's access. It runs in their terminal, sees their environment variables and can use every token and cloud credential configured there. When the agent reads untrusted content, such as a cloned repository, that content can instruct it. The Gemini CLI flaw shows the result: a README could turn an approved command into a way to ship the developer's secrets elsewhere, without the developer noticing.

Reducing the risk means keeping long-lived secrets out of developer environments, giving agents their own narrowly scoped and short-lived credentials, running agents against untrusted code only in sandboxes, and treating allow-lists as a security boundary that must parse commands strictly. See our AI Coding Agents Security Guide and Secrets Management Guide.

Recommendations

  • Update AI coding tools promptly. Upgrade Gemini CLI to 0.1.14 or later.
  • Sandbox agents on untrusted code. Run AI agents against unfamiliar repositories only in isolated environments. See the AI Coding Agents Security Guide.
  • Keep secrets out of shell environments. Fetch credentials on demand from a secrets manager rather than exporting them. See our Secrets Management Guide.
  • Keep allow-lists minimal. Approve specific commands, not whole programs, and require confirmation for anything that reaches the network.
  • Treat repository content as untrusted input. Prompt injection can arrive through any file an agent reads. See the AI Agent Threat Modelling Guide.

Frequently asked questions

Was Gemini CLI breached?

No. Tracebit found a vulnerability that could let a poisoned repository run hidden commands through Gemini CLI. Google fixed it in version 0.1.14, and no exploitation was reported.

How did the Gemini CLI attack work?

Instructions hidden in a README told Gemini to run a command that started with an allow-listed program such as grep, followed by a semicolon and a malicious command. Gemini ran the whole string without asking.

What could an attacker steal?

In Tracebit's demonstration, all of the developer's environment variables, which may contain API keys, tokens and other secrets. Tracebit said the command could be anything, such as installing a remote shell.

Amazon Q Developer Extension Compromise 2025 · Sentry MCP Agentjacking 2026 · AI Coding Agents Security Guide · AI Agent Threat Modelling Guide · Secrets Management Guide

How NHI Mgmt Group can help

AI coding agents inherit whatever access developers have. We help teams scope agent credentials, remove standing secrets from developer machines and set safe defaults for agent tools. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org