Google Antigravity is an “agent-first” coding IDE where you supervise autonomous agents instead of writing every line yourself — and its default settings let those agents auto-run terminal commands and browse the web with almost no human checkpoint. Within weeks of its November 2025 launch, researchers showed that default configuration exfiltrating AWS credentials to an external URL. Here’s what’s actually risky, and how to lock it down.
Get a Free Security Scan Book a Full AuditGoogle Antigravity is Google’s agent-first agentic development platform, launched in public preview on 2025-11-18 alongside Gemini 3 — a VS Code fork reoriented around autonomous agents that you supervise at the task level rather than the keystroke level. It has three surfaces: Agent Manager (a “mission control” for spawning and orchestrating multiple async agents), the Editor, and Artifacts (task lists, plans, screenshots, and browser recordings you comment on inline). Agents read and write code, run commands, drive a real browser, and call MCP tools on your behalf. It’s free for individuals in preview, and you can choose Gemini 3 Pro (default), Claude Sonnet 4.5, or GPT-OSS as the underlying model. Worth distinguishing from two other Google coding surfaces: Gemini Code Assist (an IDE plugin tied to Google Cloud/Vertex AI, enterprise-tiered) and Gemini CLI (an open-source terminal agent) — this page covers Antigravity specifically. People building with it range from solo “vibe coders” to enterprise teams, producing full-stack web apps (React/TypeScript/Node, Angular+Spring Boot, Python/Flask), SaaS products, admin dashboards, REST APIs, auth systems, Flutter mobile apps, Chrome extensions, and automation scripts.
This is Antigravity as a product and company — separate from whether the code its agents write for you is secure. The core weakness here is baked into the product’s defaults, not just its output.
These are the failure patterns security researchers and Zooc Digital audits actually find in Antigravity-built apps and in the agent’s own behavior.
Veracode’s Spring 2026 report found Gemini 3 only marginally better than 2.5, with roughly 55–60% security pass rates (meaning 40–45% of code still has vulnerabilities). AppSecSanta’s 2026 study found Gemini 2.5 Pro vulnerable to 22.5% of OWASP Top 10 tests (18.2% in Python, 26.7% in JavaScript). A large-scale “in the wild” study found Gemini has the highest commit-issue rate of any major model at 29.1%, versus 17.4% for Copilot.
The fix: SAST/DAST scan every agent-generated commit before merge, regardless of which underlying model produced it.
Because Antigravity agents read web pages, READMEs, blog posts, and source files as part of their normal workflow, hidden instructions planted in any of that content can coerce the agent into taking actions the developer never asked for — and Antigravity’s permissive defaults mean there’s often no human checkpoint before it acts.
The fix: treat any untrusted repo, webpage, or document the agent reads as a potential attack vector, and require explicit approval for actions triggered by content the agent just read.
With terminal execution set to “Auto” and the Agent Review Policy set to “Agent Decides” out of the box, an injected instruction can execute shell commands with no approval step at all — this is the setting combination behind most of the incidents below.
The fix: switch Agent Review Policy away from “Agent Decides” and terminal execution away from “Auto” before pointing Antigravity at any repository you don’t fully trust.
Security researchers demonstrated agents reading .env files (including AWS credentials) and exfiltrating them, and separately showed the agent bypassing the project’s default .gitignore restrictions via terminal commands to reach files that should have been off-limits.
The fix: keep secrets out of the working directory entirely (use a secrets manager or environment injection at deploy time), and don’t rely on .gitignore as a security boundary against an agent with shell access.
An injected instruction can invoke any connected MCP tool without a confirmation step, and Gemini 3 has been shown to follow invisible Unicode Tag characters that a human reviewer cannot see in a normal code review.
The fix: require confirmation for MCP tool calls with side effects, and add tooling that flags non-printable/invisible Unicode in reviewed files.
run_shell_command with a grep-prefix allowlist trick hiding an env+curl exfiltration. Reported 2025-06-27; fixed in v0.1.14 (2025-07-25); disclosed 2025-07-28..gemini/ agent config without review, sandboxing, or consent, enabling host code execution and supply-chain risk. Affects @google/gemini-cli below 0.39.1 and below 0.40.0-preview.3, and google-github-actions/run-gemini-cli below 0.1.22. Disclosed around 2026-04-30..env AWS credentials and private code to a webhook.site URL, abusing the default browser allowlist and “Auto” execution setting. Google’s response was an onboarding disclaimer, not a code fix..agent directory could instruct the agent to copy a malicious MCP config to the global ~/.gemini/antigravity/mcp_config.json, executing on every future launch and persisting through uninstall/reinstall. Google initially responded “Won’t Fix (Intended Behavior)” before reopening the issue.-X/--exec-batch flag to run arbitrary binaries, bypassing Strict Mode, triggerable via malicious comments in untrusted files. Patched 2026-02-28 with input validation.read_url_content, and exfiltration via markdown/HTML image rendering.If your Antigravity-built app touches regulated data, these are the gaps that show up in due diligence.
| Framework | Status on Antigravity | Learn more |
|---|---|---|
| HIPAA | No BAA on the free preview client; HIPAA-eligible coverage exists only via the Google Cloud/Vertex AI enterprise path, not the consumer IDE most developers are using. | HIPAA compliance for AI-built apps |
| FedRAMP | FedRAMP High is inherited only through Google Cloud/Vertex, not through the Antigravity preview client itself. | Compliance frameworks for AI-built apps |
| Data confidentiality / IP | Individual preview users have their prompts and code used for model training by default; only Workspace/GCP-authenticated access excludes training. Treat this as a confidentiality blocker for proprietary code. | GDPR & data compliance for AI-built apps |
| SOC 2 / PCI / change control | Permissive agent defaults (auto-execute terminal, “Agent Decides” review, webhook.site in the browser allowlist) directly conflict with least-privilege and human-approval requirements in SOC 2, PCI, and HIPAA audits. | PCI DSS for AI-built apps |
~/.gemini/antigravity/mcp_config.json for unexpected entries, and audit any .agent rule files in your projects.Antigravity is preview software with permissive defaults: agents can auto-run terminal commands and browse the web with little human checkpoint. Researchers demonstrated real data exfiltration under default settings within weeks of its November 2025 launch. It's usable, but requires tightening the Agent Review Policy and terminal execution settings first.
PromptArmor showed in November 2025 that an indirect prompt injection hidden in a blog post the agent read could spin up a malicious browser subagent that exfiltrated .env AWS credentials and private code to a webhook.site URL, exploiting the default browser allowlist and "Auto" terminal execution setting.
A CVSS 10.0 remote code execution flaw in Gemini CLI's headless/CI mode: it auto-trusted the workspace folder and loaded any .gemini/ agent config without review, sandboxing, or consent. It affects @google/gemini-cli below 0.39.1 and the related GitHub Action below 0.1.22; both are fixed in current versions.
Yes. Change the Agent Review Policy from "Agent Decides" to a manual-approval setting and switch terminal execution away from "Auto." These are the two default settings behind most of the disclosed data exfiltration and code execution incidents.
For individual users in preview, yes, by default, per Google's Additional Terms of Service, though an opt-out is available. Access through a Google Workspace or Google Cloud Platform account excludes your data from training.
Not the free preview client. HIPAA BAA coverage and FedRAMP High authorization are inherited only through the Google Cloud/Vertex AI enterprise path, not through the consumer Antigravity IDE most developers are actually using.
We audit Antigravity and Gemini-built apps for permissive agent defaults, prompt-injection exposure, leaked secrets, and compliance gaps — then fix what we find. Get a free scan to see where you stand.
Start Your Free Scan