Aaron Portnoy
This blog post highlights an attack on Google’s Antigravity AI IDE where a malicious project, even opened with the most restrictive settings, can gain command execution for all future invocations.