| Trojan Source (bidi override) - CVE-2021-42574 | Bidirectional control characters reorder how a line renders, so the code you read is not the code that runs. Shown live in the combined board. Reach: any bidi-aware renderer - code hosts, editors, and terminals that implement bidi. | Every bidi control renders as an inert, risk-coloured box or a named <U+202E> badge, so the reorder never happens (measured Safe) - dissected on output lies. |
| Homoglyph look-alikes | Non-ASCII characters identical in shape to ASCII (Cyrillic a, Greek o) make a fake command or URL read as legitimate. Reach: universal. | Every non-ASCII byte is tinted by risk class and can be named inline as <U+XXXX>, so a look-alike cannot pose as ASCII (measured Safe) - see it on output lies. |
| Invisible / zero-width characters | Zero-width and other invisibles draw nothing, so a command or a paste can carry hidden bytes you never see (the demo above), and boxed in the combined board. Reach: universal. | Each invisible byte is forced to a visible, inert box or named badge, in output and in a reviewed paste alike (measured Safe) - x-ray any string on output lies. |
| Clipboard hijack (OSC 52) | A viewed file or a program's output silently overwrites your clipboard, so your next paste inserts attacker text. Reach: terminal-dependent - we measured it: konsole, alacritty and kitty write it by default; xterm/urxvt/st, qterminal and VTE (gnome/xfce4/mate) refuse; secure-terminal refuses too. | Output can never write the system clipboard (measured Safe/off). |
| Title / tab hijack (OSC 0/2) | Any output renames your window or tab to anything - a fake "production" label, a spoofed context. Reach: most terminals - shown live in the combined board (konsole and kitty are partial exceptions). | The OS window title is never touched by output; a program-set title is shown only on the quarantined, untrusted tab line, so it cannot pose as a real label (quarantined). |
| Hyperlink spoof (OSC 8) | A terminal hyperlink whose visible label reads example.com but whose real target is set separately in the escape, so the text you click is not where you go. Reach: any OSC 8-aware terminal - neutralized on output lies. | Ships OSC 8 off by default, so the link is never made clickable and the raw target shows as inert text. |
| Escape repaint / cursor hide-text | A cursor-up plus erase-line (or a stuck red-on-red colour) rewrites or conceals output already on screen, so a build log shows PASS over the real FAIL. Reach: every ANSI terminal - measured in the comparison. | Parses no escape sequences (Not parsed) and its contrast guard forces any colour legible, so nothing a program prints can repaint the screen or reach a line already scrolled past. |
| Alt-screen forge (?1049h) | Output switches to the alternate screen, paints a fake "ALL GREEN" dashboard, then leaves - restoring your scrollback so no trace remains. Reach: every terminal supports alt-screen; the deception is the forged paint. | The default CLI line mode strips ?1049h and shows the log as inert text with scrollback intact; real full-screen programs need opt-in TUI mode. |
| Control bytes / NUL truncation | C0/C1 control bytes truncate a line at a NUL, inject escapes, or forge the prompt. Reach: universal - a cheat-sheet class on output lies. | Renders every control byte as an inert box named <U+XXXX> - nothing truncates, executes, or repaints (Not parsed). |
| Combining marks / Zalgo & fullwidth forms | Stacked combining marks (U+0300-036F) overflow a cell and disguise letters; fullwidth forms (U+FF01-FF5E) are wide look-alikes of ASCII. Reach: universal. | Both are non-ASCII, so they show as inert risk-coloured boxes or named badges; heavy Zalgo collapses to boxes even in Show mode. |
| Notification spoof (OSC 9 / 99) - CVE-2022-41322 | Program output raises a desktop notification carrying attacker text. Reach: terminals that implement OSC 9/99. | Keeps notifications off by default, so output can never raise one silently. |
| Clipboard read / query reflection (OSC 52 read, DA, answerback) | Output asks the terminal to read your clipboard, or reflects a query (title, cursor, DECRQSS) back onto your shell's input. Reach: terminal-dependent - see the comparison. | Interprets no escapes, so nothing on the output path can read the clipboard or write to the pty (measured Safe/off); clipboard read is off by default behind an ask-once-per-tab human gate. |
| ASCII look-alikes (rn = m) | Pure ASCII, no Unicode at all: exarnple.com reads as example.com because rn looks like m. Reach: universal; unaffected by any byte-surfacing tool. | Honest limit: no terminal, secure-terminal included, can flag this - there is nothing hidden in the bytes to surface. The only defense is reading character by character; the quiz trains it. |
| ClickFix / paste-and-run - T1204.004 | A fake CAPTCHA pre-loads a command onto your clipboard and tells you to paste it into a terminal. Actively exploited (Red Canary's #2 initial-access vector of 2025). Reach: in the wild now - see output lies: paste. | The paste review bar holds every paste before a byte reaches the shell, names what is hidden, and gates the send button - a multi-line or invisible-laced paste cannot auto-run. |
| Bracketed-paste bypass - CVE-2021-31701 | An escape embedded in the paste closes the bracketed-paste guard early so the tail auto-runs. Reach: terminals relying on bracketed paste - how it slips through. | Sanitizes every paste to reviewed ASCII and strips the guard-breaking escape (measured Safe), so the bypass has nothing to break. |