Get a Quote

Google Antigravity App Security Audit: Risks & Fixes

Google Antigravity is an “agent-first” coding IDE where you supervise autonomous agents instead of writing every line yourself — and its default settings let those agents auto-run terminal commands and browse the web with almost no human checkpoint. Within weeks of its November 2025 launch, researchers showed that default configuration exfiltrating AWS credentials to an external URL. Here’s what’s actually risky, and how to lock it down.

Get a Free Security Scan Book a Full Audit
What Antigravity Builds

An Agent-First IDE, Not Just Autocomplete

Google Antigravity is Google’s agent-first agentic development platform, launched in public preview on 2025-11-18 alongside Gemini 3 — a VS Code fork reoriented around autonomous agents that you supervise at the task level rather than the keystroke level. It has three surfaces: Agent Manager (a “mission control” for spawning and orchestrating multiple async agents), the Editor, and Artifacts (task lists, plans, screenshots, and browser recordings you comment on inline). Agents read and write code, run commands, drive a real browser, and call MCP tools on your behalf. It’s free for individuals in preview, and you can choose Gemini 3 Pro (default), Claude Sonnet 4.5, or GPT-OSS as the underlying model. Worth distinguishing from two other Google coding surfaces: Gemini Code Assist (an IDE plugin tied to Google Cloud/Vertex AI, enterprise-tiered) and Gemini CLI (an open-source terminal agent) — this page covers Antigravity specifically. People building with it range from solo “vibe coders” to enterprise teams, producing full-stack web apps (React/TypeScript/Node, Angular+Spring Boot, Python/Flask), SaaS products, admin dashboards, REST APIs, auth systems, Flutter mobile apps, Chrome extensions, and automation scripts.

Platform Security

Antigravity’s Own Security Posture

This is Antigravity as a product and company — separate from whether the code its agents write for you is secure. The core weakness here is baked into the product’s defaults, not just its output.

  • Certifications apply to the underlying Gemini for Google Cloud / Vertex AI, not the Antigravity preview client itself: Google holds SOC 1/2/3, ISO/IEC 27001, 27017, 27018, 27701, and ISO 42001 (AI management, May 2025). FedRAMP High and HIPAA/BAA coverage is inherited via Vertex AI / Google Cloud enterprise paths only — not the free consumer surface.
  • For individuals in preview, prompts and code are used for model improvement by default (per Google’s Additional Terms of Service), with an opt-out available. Access via Google Workspace or a GCP account excludes your data from training.
  • The agent approval model is the core weakness: the default Agent Review Policy is “Agent Decides,” default terminal execution is “Auto,” and the browser URL allowlist includes webhook.site by default — a domain commonly used to test and demonstrate data exfiltration.
  • Google’s response to several disclosed risks has been an onboarding disclaimer rather than a technical fix.
Common Vulnerabilities

What Breaks in Apps Built With Antigravity

These are the failure patterns security researchers and Zooc Digital audits actually find in Antigravity-built apps and in the agent’s own behavior.

1. Insecure code generation, in line with the rest of the category

Veracode’s Spring 2026 report found Gemini 3 only marginally better than 2.5, with roughly 55–60% security pass rates (meaning 40–45% of code still has vulnerabilities). AppSecSanta’s 2026 study found Gemini 2.5 Pro vulnerable to 22.5% of OWASP Top 10 tests (18.2% in Python, 26.7% in JavaScript). A large-scale “in the wild” study found Gemini has the highest commit-issue rate of any major model at 29.1%, versus 17.4% for Copilot.

The fix: SAST/DAST scan every agent-generated commit before merge, regardless of which underlying model produced it.

2. Indirect prompt injection drives autonomous agent actions

Because Antigravity agents read web pages, READMEs, blog posts, and source files as part of their normal workflow, hidden instructions planted in any of that content can coerce the agent into taking actions the developer never asked for — and Antigravity’s permissive defaults mean there’s often no human checkpoint before it acts.

The fix: treat any untrusted repo, webpage, or document the agent reads as a potential attack vector, and require explicit approval for actions triggered by content the agent just read.

3. Auto-run terminal + “Agent Decides” means no human in the loop

With terminal execution set to “Auto” and the Agent Review Policy set to “Agent Decides” out of the box, an injected instruction can execute shell commands with no approval step at all — this is the setting combination behind most of the incidents below.

The fix: switch Agent Review Policy away from “Agent Decides” and terminal execution away from “Auto” before pointing Antigravity at any repository you don’t fully trust.

4. Secrets exposure from .env and gitignored files

Security researchers demonstrated agents reading .env files (including AWS credentials) and exfiltrating them, and separately showed the agent bypassing the project’s default .gitignore restrictions via terminal commands to reach files that should have been off-limits.

The fix: keep secrets out of the working directory entirely (use a secrets manager or environment injection at deploy time), and don’t rely on .gitignore as a security boundary against an agent with shell access.

5. MCP tools and hidden Unicode instructions execute without confirmation

An injected instruction can invoke any connected MCP tool without a confirmation step, and Gemini 3 has been shown to follow invisible Unicode Tag characters that a human reviewer cannot see in a normal code review.

The fix: require confirmation for MCP tool calls with side effects, and add tooling that flags non-printable/invisible Unicode in reviewed files.

CVEs & Incidents

Antigravity & Gemini CLI: Disclosed Incidents

  • Gemini CLI silent RCE (Tracebit, CVSS 10, no CVE assigned) — default-config Gemini CLI silently executed arbitrary commands while inspecting an untrusted repo, via prompt injection in a README/GEMINI.md that abused run_shell_command with a grep-prefix allowlist trick hiding an env+curl exfiltration. Reported 2025-06-27; fixed in v0.1.14 (2025-07-25); disclosed 2025-07-28.
  • CVE-2026-12537 (CVSS 10.0) — Gemini CLI CI/CD remote code execution. Headless/CI mode auto-trusted the workspace folder and loaded any .gemini/ agent config without review, sandboxing, or consent, enabling host code execution and supply-chain risk. Affects @google/gemini-cli below 0.39.1 and below 0.40.0-preview.3, and google-github-actions/run-gemini-cli below 0.1.22. Disclosed around 2026-04-30.
  • Antigravity data exfiltration (PromptArmor, November 2025) — indirect prompt injection hidden in an “implementation blog” the agent read spun up a malicious browser subagent that exfiltrated .env AWS credentials and private code to a webhook.site URL, abusing the default browser allowlist and “Auto” execution setting. Google’s response was an onboarding disclaimer, not a code fix.
  • “Forced Descent” persistent code execution (Mindgard, November 2025) — a malicious rule file in a project’s .agent directory could instruct the agent to copy a malicious MCP config to the global ~/.gemini/antigravity/mcp_config.json, executing on every future launch and persisting through uninstall/reinstall. Google initially responded “Won’t Fix (Intended Behavior)” before reopening the issue.
  • Strict-Mode escape via find_by_name (Pillar Security, disclosed 2026-01-07) — an unvalidated pattern parameter allowed injecting fd’s -X/--exec-batch flag to run arbitrary binaries, bypassing Strict Mode, triggerable via malicious comments in untrusted files. Patched 2026-02-28 with input validation.
  • Five unpatched issues (Embrace The Red, November 2025) — auto-run RCE via prompt injection, invisible Unicode instructions, no human-in-loop for MCP tools, exfiltration via read_url_content, and exfiltration via markdown/HTML image rendering.
Compliance

Compliance Blockers for Antigravity Apps

If your Antigravity-built app touches regulated data, these are the gaps that show up in due diligence.

FrameworkStatus on AntigravityLearn more
HIPAANo BAA on the free preview client; HIPAA-eligible coverage exists only via the Google Cloud/Vertex AI enterprise path, not the consumer IDE most developers are using.HIPAA compliance for AI-built apps
FedRAMPFedRAMP High is inherited only through Google Cloud/Vertex, not through the Antigravity preview client itself.Compliance frameworks for AI-built apps
Data confidentiality / IPIndividual preview users have their prompts and code used for model training by default; only Workspace/GCP-authenticated access excludes training. Treat this as a confidentiality blocker for proprietary code.GDPR & data compliance for AI-built apps
SOC 2 / PCI / change controlPermissive agent defaults (auto-execute terminal, “Agent Decides” review, webhook.site in the browser allowlist) directly conflict with least-privilege and human-approval requirements in SOC 2, PCI, and HIPAA audits.PCI DSS for AI-built apps
Fix-It Checklist

Security Checklist for Your Antigravity App

  • Change the Agent Review Policy away from “Agent Decides” and terminal execution away from “Auto” before working with any untrusted repository.
  • Remove webhook.site (and any other testing/exfiltration-friendly domain) from the browser URL allowlist.
  • Keep all secrets and credentials out of the working directory — do not rely on .gitignore as an agent security boundary.
  • Update Gemini CLI to at least v0.40.0-preview.3 (or 0.39.1) and any GitHub Action to at least v0.1.22 to close CVE-2026-12537.
  • Check ~/.gemini/antigravity/mcp_config.json for unexpected entries, and audit any .agent rule files in your projects.
  • Require confirmation for MCP tool calls that have side effects (writes, network calls, shell execution).
  • Run SAST/DAST on every agent-generated commit before merge, independent of which model wrote it.
  • Do not point Antigravity’s agents at real customer data or production credentials while it remains preview software.
FAQ

Google Antigravity Security: Frequently Asked Questions

Is Google Antigravity safe to use?

Antigravity is preview software with permissive defaults: agents can auto-run terminal commands and browse the web with little human checkpoint. Researchers demonstrated real data exfiltration under default settings within weeks of its November 2025 launch. It's usable, but requires tightening the Agent Review Policy and terminal execution settings first.

What is the Antigravity data exfiltration vulnerability?

PromptArmor showed in November 2025 that an indirect prompt injection hidden in a blog post the agent read could spin up a malicious browser subagent that exfiltrated .env AWS credentials and private code to a webhook.site URL, exploiting the default browser allowlist and "Auto" terminal execution setting.

What is Gemini CLI CVE-2026-12537?

A CVSS 10.0 remote code execution flaw in Gemini CLI's headless/CI mode: it auto-trusted the workspace folder and loaded any .gemini/ agent config without review, sandboxing, or consent. It affects @google/gemini-cli below 0.39.1 and the related GitHub Action below 0.1.22; both are fixed in current versions.

Can I disable Antigravity's auto-run agent behavior?

Yes. Change the Agent Review Policy from "Agent Decides" to a manual-approval setting and switch terminal execution away from "Auto." These are the two default settings behind most of the disclosed data exfiltration and code execution incidents.

Does Google Antigravity train on my code?

For individual users in preview, yes, by default, per Google's Additional Terms of Service, though an opt-out is available. Access through a Google Workspace or Google Cloud Platform account excludes your data from training.

Is Google Antigravity HIPAA or FedRAMP compliant?

Not the free preview client. HIPAA BAA coverage and FedRAMP High authorization are inherited only through the Google Cloud/Vertex AI enterprise path, not through the consumer Antigravity IDE most developers are actually using.

Is Your Antigravity App Actually Secure?

We audit Antigravity and Gemini-built apps for permissive agent defaults, prompt-injection exposure, leaked secrets, and compliance gaps — then fix what we find. Get a free scan to see where you stand.

Start Your Free Scan