Antigravityブラウザエージェントにおいて、.envファイルからAWS認証情報を盗み出す手法が報告されており、注意が必要です。
This one is pretty nasty - it tricks Antigravity into stealing AWS credentials from a .env file (working around .gitignore restrictions using cat) and then leaks them to a webhooks debugging site that's included in the Antigravity browser agent's default allow-list https://t.co/HP9ecUFVhv
— Simon Willison (@simonw) November 25, 2025