Docs menu

No invisible Unicode tag characters

BLOCK Frame security/no-invisible-tag-chars
On this page

Reject files containing characters in the Unicode tag block (U+E0000–U+E007F). These render as zero pixels in every editor and terminal yet carry full payload - the canonical channel for hiding prompt-injection instructions inside otherwise innocuous text.

Typical failure shape: a “harmless” markdown snippet, README, or comment includes a tag-encoded instruction stream that an LLM agent reading the file will interpret as a directive. The human reviewer sees nothing unusual; the agent obeys what’s hidden.

What this catches#

Any rune in the range U+E0000 – U+E007F (the Unicode “Tags” block, including the language tag U+E0001 and the tag-cancel U+E007F). These codepoints have no legitimate use in modern source code.

Fix#

Remove the offending character. On the command line:

LC_ALL=C grep -P '[\x{E0000}-\x{E007F}]' <file>

Tag-block characters are essentially never benign in code or documentation. There is no recommended suppression - if you have a real need for tag-encoded text (rare research / forensic fixtures), suppress at the file level with # appframes:disable security/no-invisible-tag-chars and document why in the same file.

Reference#

  • Unicode Standard, Chapter 23 - Tags
  • “Invisible prompt injection via Unicode tags” (multiple 2024–2025 AI-safety writeups)

Deliberately not flagged#

  • Subdivision flag emoji (🏴󠁧󠁢󠁳󠁣󠁴󠁿, 🏴󠁧󠁢󠁷󠁬󠁳󠁿) - a flag is U+1F3F4 plus tag letters terminated by U+E007F, the standard encoding. Only a well-formed sequence is skipped: an unterminated run, or a cancel tag with nothing before it, is still reported.

BLOCK rejects the push. Turn frames on per repo on the dashboard's Policy page - see choosing what the gate checks.

Source on GitHub Live demo How it works Questions: contact@nimblegate.com