AGENTS.md can lie to your eyes.Invisible Unicode payloads — Tag chars, zero-width separators, bidi-override re-orderings, homoglyph swaps — let anyone with commit access ship hidden instructions to your AI coding agent. glyph-trap decodes them and shows you the bytes your agent will silently obey.
Loading live counter…
glyph-trap detects invisible-Unicode payloads inside AI-agent
instruction files: AGENTS.md, CLAUDE.md,
GEMINI.md, SKILL.md,
.cursorrules, .windsurfrules,
.clinerules, .mdc (Cursor rules),
.claude/settings.json, and a few more.
raw.githubusercontent.com — raw bytes per file.No seed data, no Math.random() jitter, no placeholder rows.
If GitHub returns zero results this hour, the counter stays where it is.