Rules-file Injection Meaning?
4.0BRAINROT SCORERules-File Injection Hiding malicious instructions inside a project's coding-agent rules file so they execute automatically the moment any developer opens the repo in an agent-integrated editor, without the developer ever writing or approving the instruction themselves.
Origin:A specific variant of prompt injection targeting the persistent, auto-loaded configuration files coding agents read at the start of every session.
First Seen:2025
Peak Era:2026 (Coding Agent Security)
Aura Impact:+1 Aura (Diffing Rules Files on Every Pull From an Unfamiliar Repo) / -2 Aura (Cloning a Repo and Letting the Agent Read Its Rules File Unreviewed)
EXAMPLE USAGE
"The malicious fork's rules-file injection quietly told every agent that opened it to also scan for and upload any .env files it found."
Want the full breakdown — categories, trend velocity, platform distribution, and community voting on Rules-File Injection? Visit the full dictionary entry for Rules-File Injection.