The Ghost in the Tokenizer: ai-copilot-payload-builder

How invisible Unicode "Sneaky Bits" turn benign documents into high-privilege AI exploits.

• View on GitHub • More from shuvonsec

A wide shot of a high-tech laboratory where a scientist looks at a completely empty glass pedestal through a special lens that reveals a glowing, complex machine inside the void.
The tokenizer sees what the human eye cannot.

Generate Claude Code bug bounty skills from public HackerOne reports and GitHub writeups — no private reports needed.

shuvonsec, Project Maintainer · Repository: shuvonsec/public-skills-builder

Key Takeaways

The Attack You Can't See

The era of "What You See Is What You Get" is over. When a human moderator reviews a document, they see letters, numbers, and punctuation. When a Large Language Model (LLM) processes that same document, it sees tokens. The gap between those two realities is where modern prompt injection lives.

Enter ai-copilot-payload-builder, a specialized security tool by researcher shuvonsec. It demonstrates a technique known as Unicode Smuggling. Instead of trying to trick an AI with clever phrasing like "ignore previous instructions," it encodes malicious commands into non-rendering Unicode characters. To a human, a file looks like a harmless bug report. To an AI Copilot reading that file, it's a high-priority command to exfiltrate sensitive data.

Bridge the Tokenizer Gap

The core of the tool relies on "Sneaky Bits"—specifically U+2062 (Invisible Times) and U+2064 (Invisible Plus). These are invisible mathematical operators. They render as absolutely nothing on a screen. However, they are not stripped out by standard whitespace sanitizers or basic regex filters.

How invisible Unicode characters bypass visual inspection but are processed by the LLM tokenizer.

More importantly, LLM tokenizers (like Byte-Pair Encoding) process these invisible characters as distinct tokens. The payload builder takes an attack string, converts it to binary, and maps the 0s and 1s to these invisible characters. It then embeds this invisible stream into a visible carrier text.

The Redundancy Sandwich

Generating an invisible payload is only half the battle. LLMs are notoriously fickle about where they pay attention within a large document—a phenomenon known as the "Lost in the Middle" problem. To counter this, the payload builder employs a redundancy strategy.

A close-up of a mechanical sandwich. The bread is clear, readable text, while the meat inside is a dense, dark mesh of gears (the hidden payload) that is only visible when the sandwich is sliced open.
The tool injects the payload at multiple structural points to ensure execution.

The build_payload function injects the hidden stream at the beginning, middle, and end of the visible text. This "sandwich" approach guarantees that regardless of how the AI assistant chunks or truncates the input document, a complete copy of the malicious instruction is processed.

Beyond "Ignore Previous Instructions"

This tool highlights the shift from direct prompt injection (where the user attacks the AI) to Indirect Prompt Injection (IPI). In an IPI scenario, the attacker doesn't interact with the AI at all. They simply leave a poisoned document on the web or in a repository. When a developer uses an AI Copilot to summarize or debug that document, the AI ingests the payload.

Evasion LevelTechniqueResult against Guardrails
Simple Text"Ignore all instructions"Blocked by basic LLM safety guardrails.
Character Swapping"1gn0r3"Blocked by fuzzy-matching/semantic filters.
Unicode SmugglingInvisible U+2062 charactersBypasses human review, WAFs; processed as raw logic.

The Ethical Sandbox

While the ai-copilot-payload-builder repository itself is elusive, it is part of a broader ecosystem of red-teaming tools developed by shuvonsec. Another tool, public-skills-builder, leverages similar analytical approaches to offensive security.

Portrait of shuvonsec

These tools prioritize zero-dependency, portable Python scripts. In the world of security research, a tool that can run anywhere without a complex installation process is invaluable for testing environments rapidly and reliably.