Skip to content

Hide Navigation Hide TOC

Unicode Tag Character Smuggling - ATR-2026-00129 (f2ab7f7f-9942-5f80-8465-371df1822d54)

Detects Unicode Tag characters (U+E0001-U+E007F) and other invisible Unicode ranges used to smuggle hidden instructions in SKILL.md files. These characters are invisible in most editors and renderers but are processed by AI agents as text. Snyk ToxicSkills research (Feb 2026) documented this as "ASCII smuggling" — invisible payloads that agents read but humans cannot see.

Cluster A Galaxy A Cluster B Galaxy B Level
Unicode Tag Character Smuggling - ATR-2026-00129 (f2ab7f7f-9942-5f80-8465-371df1822d54) Agent Threat Rules ML Supply Chain Compromise (d2cf31e0-a550-4fe0-8fdb-8941b3ac00d9) MITRE ATLAS Attack Pattern 1