SG-100: Agent-propagated / credential exfiltration

Severity: CRITICAL

Instruction file tells the agent to inject an outbound network call into every generated file, or to harvest environment secrets/credentials and POST them to an external host. Covers prompt-exfil variants that carry no covert keyword and no $USER_PROMPT token (real example: NiranjanJ2/permission-test .gemini/GEMINI.md, 2026-06).

Fires when

Remediation

Remove the instruction block. An instruction file should never tell the agent to inject network calls into generated code or to collect environment secrets/credentials and send them off-host.