Skip to content
augur

What it finds

Trojan Source and bidi overrides

Direction controls reorder how text is displayed without touching how it is parsed. In source, that makes the program a reviewer reads and the program the compiler builds two different things.

U+202E RIGHT-TO-LEFT OVERRIDEU+2066CVE-2021-42574bidi attack

The comment that is not a comment

$ augur scan auth.go
auth.go (text): 5 finding(s)

BIDI
   [alarm] offset 73 — U+202E RIGHT-TO-LEFT OVERRIDE
   [notice] offset 76 — U+2066 LEFT-TO-RIGHT ISOLATE
   [notice] offset 100 — U+2066 LEFT-TO-RIGHT ISOLATE
   [notice] offset 103 — U+2069 POP DIRECTIONAL ISOLATE

WHITESPACE
   [notice] offset 99 — 1 trailing whitespace character(s)
       1 bytes

The override sits inside a comment. Displayed, the line reads as though the privileged branch is guarded; parsed, the guard is not there and the function returns on the other branch.

It is not only source files

The same characters in a hook command, an MCP server entry or a permission allowlist mean an agent executes one thing while the file appears to say another. augur scans those files too, and reports the finding as a JSON path rather than quoting the line, because those files hold tokens.

Removed, and then checked from disk

$ augur clean auth.go
wrote auth.clean.go
verified: 5 removed, 0 finding(s) deliberately left in place

$ augur scan auth.clean.go
auth.clean.go (text): nothing hidden found

Removable, unlike a lookalike letter: deleting a direction control does not change what any word says. It is still a decision — a file that genuinely mixes scripts may want them — so the viewer lets you take them one at a time.

$curl -fsSL https://raw.githubusercontent.com/dejo1307/augur/main/install.sh | sh

Related:Scanning a repositoryANSI escape sequenceseverything it looks for