GuardFall enables attackers to inject malicious commands into AI agents through Bash tricks that circumvent text-based security filters by expanding the harmful commands only after internal inspection by the shell.
GuardFall exploits decades-old Bash techniques such as quoting tricks and environment variables to bypass security filters and execute arbitrary commands in AI agents.