Book a 30-minute demo →
← Back to blog
Anomity robot illustrating Google Antigravity Security: An Agentic IDE Now Ships as an Editor Extension
Insights

Google Antigravity Security: An Agentic IDE Now Ships as an Editor Extension

TL;DR
  • Released 20 August 2026. That is the date on Google's own blog post, "Introducing IDE Extensions." Google's own @antigravity post on X named four editors - Visual Studio Code, Visual Studio, Zed and JetBrains - the same four AlternativeTo covered on 25 August; the blog post and enterprise documentation add a fifth, Xcode, listed as Preview.
  • A distribution change, not a feature review. An agentic IDE that shipped as its own application produced an install artifact. As editor extensions it arrives through five marketplaces the endpoint owner does not run.
  • Governance is tenant-side, and partly preview. Google bundled Antigravity into Gemini Enterprise licenses on 21 August 2026 with sandboxing, browser and MCP access policy, audit logging and spend caps. Its enterprise documentation lists Visual Studio Code with no preview qualifier; Visual Studio, JetBrains, Zed and Xcode are all marked Preview.
  • Personal sign-in leaves the tenant. Those controls bind a Gemini Enterprise license and a corporate identity. A developer who installs the VS Code extension and signs in with a personal Google Account is authenticating outside all of them.
  • Safe defaults, drifting configuration. Google documents that agents ask before running any terminal command and read and write only inside the provided folders. The risk is per-project drift to "Full machine" or "Unrestricted", and Allow lists that grow quietly.
  • A patched prompt-injection record, on the worst artifact type. Pillar Security reported a find_by_name flag-injection chain on 7 January 2026, patched 28 February 2026. Antigravity now ships through the same two channels that carried Solidity Pro (Open VSX) and the Amazon Q wiper update and PolinRider's artifacts (the VS Code Marketplace).

Google Antigravity security stopped being an application-inventory question on 20 August 2026. That is the date on Google's own blog post, "Introducing IDE Extensions", which put its agentic IDE inside Visual Studio Code, Visual Studio, Zed, JetBrains and Xcode. AlternativeTo covered it five days later, in an item bylined Fla, and counted four editors.

This is a distribution event, not a product to review on features. An agentic IDE that existed only as its own application was at least visible: an installer, a bundle, a version, a row in a software inventory. As editor extensions it arrives through marketplaces the endpoint owner does not run. It is the newest entry in the problem set covered in Securing AI Coding Agents and CLIs, next to Cursor, Copilot, Codex and Claude Code. Only the artifact type changed, and it changed to the worst one.

What the sources say, and where they actually conflict

Start with the vendor, because the vendor published first. Google's post frames the extensions as deliberately small: "Rather than trying to turn traditional editors into heavy multi-agent hubs, we built lightweight, high-performance integrations across all supported editors." The very next sentence promises rather more - developers install Antigravity "to gain access to conversations, customizations, and multi-agent orchestration that shares context with the rest of the Antigravity ecosystem". AlternativeTo's item repeats that capability list almost word for word, adds that the extensions "share context with the wider Antigravity ecosystem to support integrated workflows", and credits a post on X from Google for Developers rather than Google's own announcement. So the capability claim originates with Google, not with the aggregator.

That matters for how many disagreements there really are. We went looking for three. Reading Google's own post closes one outright and relabels a second, and the honest count is two.

  • The date is settled, not disputed. Google's post is dated 20 August 2026; byteiota and The New Stack agree, and The Register covered the Gemini Enterprise bundling on 21 August. AlternativeTo's 25 August item is coverage of a five-day-old shipment, not a second launch. There is no conflict here to flag.
  • The editor count is a real omission. AlternativeTo names four. Google names five, adding Xcode, and its enterprise documentation lists all five. That does not weaken the argument; it adds a marketplace to it, and one more row to the AI agent inventory you are trying to keep current.
  • Multi-agent orchestration is the one genuine capability conflict, and it is partly Google against Google. Google's launch post puts orchestration in the extensions. byteiota, writing on 23 August 2026, says "Multi-agent orchestration and Antigravity's built-in Chromium browser subagent still require the desktop app." Google's Antigravity 2.0 feature documentation places the integrated terminal and the VCS panel on the desktop app, while its separate "Antigravity for IDEs" documentation gives the extensions a narrower headline list - "converse with agents in dedicated side panels, review granular inline diffs, inspect interactive plans, and execute multi-step engineering tasks" - but does carry its own Browser section, with allowlist, denylist and separate-Chrome-profile pages under it.

We flag that one rather than resolve it, because resolving it changes nothing about what lands on the laptop. Wherever the heavier orchestration actually runs, Google documents "a unified authentication system across all IDE extensions, the Antigravity CLI, and Antigravity 2.0 (Desktop)". One identity, governed or ungoverned, follows the developer across every surface.

Five marketplaces, and none of them yours

Editor surfaceDistribution channelStatus, per Google's documentation (August 2026)
Visual Studio CodeVS Code Marketplace, for macOS, Linux and WindowsThe only surface Google lists without a qualifier
Visual StudioVisual Studio Marketplace or the in-IDE extension manager, targeting Visual Studio 2026Preview
JetBrains IDEs (IntelliJ IDEA, PyCharm, WebStorm, GoLand, CLion, Rider "and more")One-click install inside the IDE; Google documents a requirement of version 2026.2.1 or laterEnterprise support in Preview
ZedOne-click install inside the editorEnterprise support in Preview
XcodeOnboarded through Xcode's Intelligence settings panel; Google documents a requirement of Xcode 27 beta 6 or later; not among AlternativeTo's fourEnterprise support in Preview

The middle column is the argument. Each entry is a separate submission process, review and release cadence for the same agent, and none belongs to the organization whose laptops it lands on. Ask which version is running on your fleet and the answer depends on which editor each developer uses.

The install itself is the second structural point. Installing an editor extension is a marketplace transaction inside an application already present, so it creates no MSI, PKG or macOS application bundle - the artifact software-inventory tooling keys on. That is a general property of extension distribution, not a claim that extensions bypass endpoint security. An agentic IDE arriving stops resembling a software install and starts resembling a plugin update nobody approved. Same asymmetry we work through at fleet scale in Governing AI Coding Assistants Across Your Fleet.

What Google Antigravity security controls actually cover, and where they stop

Google announced on 21 August 2026 that Antigravity is bundled into eligible Gemini Enterprise Standard, Plus and Standard Emerging Market licenses, with admin controls covering workspace sandboxing, browser and MCP server access, central audit logging, spend thresholds, pooled token quotas and usage metrics. Audit logging is a single toggle "capturing prompts, agent responses, and metadata for compliance reporting". The Register reported the same set that day. This is a fuller control surface than most agent vendors shipped in year one.

Read the coverage list carefully, though. Google's enterprise documentation states that enterprise integration is supported for Antigravity 2.0, the CLI and the IDE extensions - and then lists the extension surfaces as Visual Studio Code, Visual Studio (Preview), JetBrains (Preview), Zed (Preview) and Xcode (Preview). Only the VS Code extension carries no qualifier; on the other four the vendor itself says preview. The same documentation adds that "Antigravity IDE (standalone) is currently not supported for enterprise deployments", which is a fourth Antigravity surface again, distinct from both the desktop app and the extensions.

The remaining limit is structural rather than a shortcoming. Every one of those controls is console-side and predicated on a Gemini Enterprise license plus corporate identity. Google documents two sign-in paths: individuals use a personal Google Account, enterprises sign in with Gemini Enterprise or Google Cloud project credentials. So the gap is narrower than "nobody can see it" - but it is still a gap, and it is the one that matters on a managed laptop. A developer who signs in personally authenticates outside the tenant, so the console's audit log, MCP policy and sandboxing describe an install that is not theirs. A tenant-scoped record of prompts answers a different question than the one in Building an Audit Trail for AI Agents: what is installed, on which machine, configured how.

The terminal is a desktop capability today, and a direction of travel

A second AlternativeTo item, published 26 August 2026 by Mauricio B. Holguin, reports that Antigravity 2.0 added Git version control in the right-side panel, branch tracking and an embedded terminal. Google's own blog of 24 August 2026 describes a VCS panel with three views - Agent Edits, Uncommitted and Branch - tracking all changes against the branch, including "side effects from a bash script editing files", plus an embedded terminal for running tests, linters, build tools, package management and any other command line tool the developer needs.

Be precise about where that lives. Google's feature documentation places both the terminal and the VCS panel under Antigravity 2.0, the desktop application, and documents the extensions separately under "Antigravity for IDEs", whose own feature list has no terminal in it. The terminal is not a shipped extension feature and we will not pretend otherwise. What it shows is where an agent surface trends: toward a shell. An agent with a terminal is an agent with your shell.

Google's defaults are sound. Its documentation states that "By default, agents will request your explicit permission before running any terminal commands" and that "By default, your agent can only read and write within the provided folders". It documents three presets - Default, Full machine and Unrestricted - the latter two granting read and write across the full machine, rules evaluated Deny over Ask over Allow, scoped per project. Terminal execution has two modes: Request Review, prompting before every command not on a configurable Allow list, and Always Proceed, which Google labels high autonomy, high risk. Set that against Claude Code vs Codex vs Cursor permission models: the same design, different names.

The risk is not an unsafe default, it is drift. Presets are per project, Allow lists grow, and the developer who flips a project to Unrestricted at 6pm to unblock a build files no ticket. Google's own agent supplies the precedent: Gemini CLI's allowlist bypass into silent command execution is why "the agent asks first" is a default, not a boundary.

More artifacts travel with each install than the extension itself. Google's MCP documentation names four surfaces - Antigravity 2.0, Antigravity IDE, the Antigravity CLI and the Antigravity SDK - and Google surfaces that same MCP guide under Customizations in its "Antigravity for IDEs" documentation, alongside skills, rules, workflows, plugins and hooks. The Gemini Enterprise announcement lists browser and MCP server access among the admin controls covering the extensions. Every install can therefore carry its own MCP and customization state, reproducing the config drift documented for Cursor's .cursorrules and MCP surface.

IDE extensions have the worst record of any artifact type here

This is not speculation about the extension channel. It is what already happened on it.

CaseWhat happenedWhy it bears on an agent shipping as an extension
Solidity Pro on Open VSXExtensions that stole AI, cloud and SSH credentials off developer machinesThe extension was the payload. Open VSX is not a Google channel; cited as itself.
Amazon Q Developer for VS CodeA wiper prompt-injection payload shipped in a signed extension updateWhat a poisoned agent extension does through a marketplace update channel.
PolinRiderMalicious npm and VS Code artifacts across 1,900+ GitHub repositoriesA real campaign that chose the extension channel to reach developer machines.
GitHub Copilot in VS CodeCVE-2025-53773: an agent extension reached code execution by rewriting its settingsAn agent that can edit configuration can edit the configuration constraining it.

None of that accuses Google's listings or says marketplaces skip review. It says the surface has a history, and an agentic IDE arriving on it inherits that history whatever the vendor's reputation.

Shared context, and the question worth asking the vendor

AlternativeTo reports that the extensions share context with the wider Antigravity ecosystem, and Google documents unified authentication across the extensions, the CLI and the desktop app. Both are vendor-stated features. Our reading, and it is a reading rather than a finding, is that an agent surface consuming untrusted input in one editor and carrying context to another is on paper a propagation path. No source demonstrates cross-editor propagation in Antigravity and we have not tested it. The closest evidence is Comment and Control, where GitHub comments hijacked Claude Code, Gemini CLI and Copilot agents.

Antigravity's own record gives the shape of the risk, and it is patched. The Hacker News reported on 21 April 2026 that Dan Lisichkin of Pillar Security chained permitted file creation with weak input sanitization in the native file-search tool: "By injecting the -X (exec-batch) flag through the Pattern parameter [in the find_by_name tool], an attacker can force fd to execute arbitrary binaries against workspace files." That escaped Strict Mode, which "limits network access, prevents out-of-workspace writes, and ensures all commands are being run within a sandbox context". Reported 7 January 2026, patched 28 February 2026; no CVE has been published for it as of this writing. SecurityWeek added that the trigger was indirect prompt injection via malicious comments in untrusted source files - Indirect Prompt Injection, Explained, delivered by cloning a repo.

Separately, SecurityWeek reported in April 2026 that Malwarebytes found a fake site, google-antigravity.com, distributing a trojanized installer that bundled the legitimate IDE with malicious PowerShell stealing browser passwords, cookies and autofill data. It targeted the desktop installer, not the extensions. Same play as the SEO-poisoning campaign behind fake Gemini CLI and Claude Code installers: popular agent, plausible download page, infostealer.

What Google Antigravity security looks like on an endpoint you manage

Ask what is physically present on a laptop afterwards. Five things, only one of which is the install event:

  • An extension, in one of five editors, updating on that editor's channel, not yours.
  • A signed-in identity, your Gemini Enterprise tenant or a personal Google Account. The console audit log describes only the first.
  • Per-project security settings: which preset is active, and which terminal mode.
  • An Allow list and a Deny list for terminal commands, edited locally, growing.
  • MCP server entries, since Google documents MCP configuration under the customizations for its IDE extensions as well as for the desktop app and CLI - which puts each install inside the scope of MCP Server Security.

Four of those five are configuration state, not an install. That is the case for treating the endpoint as the system of record rather than a vendor console or a self-published catalog, the argument for endpoint discovery over agentic resource discovery.

The governable object is not the arrival. It is what it leaves behind.

How Anomity inventories Google Antigravity on the endpoint

An unprivileged Endpoint Sensor for Windows, macOS and Linux inventories eight AI artifact types per endpoint - AI agents, MCP servers, extensions, plugins, skills, secrets, hooks, and CLIs. Extensions are one of the eight, which is why an agentic IDE arriving as an editor extension is a data-collection question rather than a new integration. Inside Anomity Discovery covers how.

  • Inventory. Every endpoint carrying an Antigravity extension, in which editor, with its MCP server entries and hook definitions beside it. That answers what the vendor console cannot: which machines, which channel, and whether the install is inside your tenant.
  • Allow, deny or log at the hook, where one exists. Anomity enforces at an agent's own enforcement point, for example Claude Code's PreToolUse hook, per How Claude Code Hooks Work. Antigravity documents a hooks.json of its own, with PreToolUse and PostToolUse events, for the IDE extensions as well as the desktop app - which makes that file an artifact worth inventorying in its own right, since a hook is a shell command the agent runs. Anomity's enforcement runs at Claude Code's hook today, so for an Antigravity install what you get is inventory and change detection.
  • A queryable 90-day audit trail of every added, changed or removed artifact - so a preset flipped to Unrestricted becomes a timestamped event on a named endpoint.
  • Metadata only, secrets redacted on the endpoint - never source code, prompts or secret values. Events route to SIEM, Slack, email or Jira. Anomity is SOC 2 Type II and complements, not replaces, Network, EDR, DLP and GRC.

Google did the harder half well: real admin controls, real audit logging, safe defaults, documentation of what each preset changes. The half left over is the usual one - knowing which machines are inside that arrangement and which run the same agent on a personal account with a preset nobody enumerated. Book a demo to answer that from the endpoint, not the console.

Frequently asked questions

What did Google Antigravity actually release in August 2026?

Google published "Introducing IDE Extensions" on the Antigravity blog on 20 August 2026, putting Antigravity inside Visual Studio Code, Visual Studio (Preview), JetBrains, Zed and Xcode. Google's own wording is that developers gain "conversations, customizations, and multi-agent orchestration that shares context with the rest of the Antigravity ecosystem". AlternativeTo repeated that capability list on 25 August 2026, in an item bylined Fla, but named only four editors, omitting Xcode. byteiota and The New Stack also date the release to 20 August. Treat 20 August 2026 as the release date and Google's five-editor list as the authoritative one.

Why does Google Antigravity security change when it ships as an IDE extension?

Because the artifact type changes. An application produces an installer and an application bundle, which is what software-inventory tooling keys on. Installing an editor extension is a marketplace transaction inside an editor that is already present, so it produces no MSI, PKG or macOS application bundle. That is not a claim that extensions are invisible to endpoint security. It is a narrower point: the moment an agentic IDE arrives on a laptop stops looking like a software install, and starts looking like a plugin update nobody was asked to approve.

Does Google offer enterprise controls for Antigravity?

Yes. On 21 August 2026 Google announced that Antigravity is bundled into eligible Gemini Enterprise Standard, Plus and Standard Emerging Market licenses, with workspace sandboxing, browser and MCP server access controls, central audit logging, granular spend thresholds, pooled token quotas and usage metrics. Audit logging is a single toggle "capturing prompts, agent responses, and metadata for compliance reporting". Google's enterprise documentation states the controls cover Antigravity 2.0, the CLI and the IDE extensions, but lists Visual Studio (Preview), JetBrains (Preview), Zed (Preview) and Xcode (Preview), with Visual Studio Code the only unqualified entry. It adds that "Antigravity IDE (standalone) is currently not supported for enterprise deployments".

Can Antigravity agents run shell commands on a developer machine?

Google's documentation states that "By default, agents will request your explicit permission before running any terminal commands" and that "By default, your agent can only read and write within the provided folders". It documents three security presets - Default, Full machine and Unrestricted - where the latter two extend read and write access over the full machine, with rules evaluated Deny over Ask over Allow and settings scoped per project. Terminal execution offers Request Review and Always Proceed modes, the latter labeled high autonomy, high risk. The default is safe. The concern is per-project drift nobody is enumerating.

Is the embedded terminal part of the IDE extensions?

Not per Google's own documentation. Google's Antigravity blog of 24 August 2026 describes an embedded terminal and a Git version control panel with Agent Edits, Uncommitted and Branch views, and its Antigravity 2.0 feature documentation lists both under Antigravity 2.0, the desktop application, reachable from the sidebar or with Ctrl or Cmd plus backtick. The separate "Antigravity for IDEs" documentation lists no terminal; its feature set is the side panel, inline diffs, plans, artifacts, screenshots and a browser integration. AlternativeTo's 26 August 2026 item covers the same 2.0 additions. Do not assume a terminal inside the editor extensions; do assume the direction of travel for agent surfaces generally.

Has Antigravity had a security incident?

It has a patched, publicly documented one. The Hacker News reported on 21 April 2026 that Dan Lisichkin of Pillar Security found a prompt-injection-to-remote-code-execution chain: injecting the -X (exec-batch) flag through the Pattern parameter of Antigravity's native find_by_name tool forced fd to execute arbitrary binaries against workspace files, escaping a Strict Mode that "limits network access, prevents out-of-workspace writes, and ensures all commands are being run within a sandbox context". It was reported 7 January 2026 and patched 28 February 2026. SecurityWeek added on 22 April 2026 that the trigger was indirect prompt injection via malicious comments in source files from untrusted repositories. No CVE has been published for it as of this writing.

Does shared context mean a prompt injection in one editor reaches the others?

No source shows that, and we are not asserting it. AlternativeTo reports that the extensions "share context with the wider Antigravity ecosystem to support integrated workflows", and Google documents "a unified authentication system across all IDE extensions, the Antigravity CLI, and Antigravity 2.0 (Desktop)". Those are vendor-stated features. The propagation concern is our reading of them, and it belongs in a vendor questionnaire rather than in a finding. The closest published evidence for one poisoned input reaching several agent surfaces is the Comment and Control research across Claude Code, Gemini CLI and Copilot agents.

What should a security team do about Antigravity this week?

Inventory before policy. Find which endpoints carry an Antigravity extension and in which editor, which identity it is signed in with - a corporate Gemini Enterprise identity or a personal Google Account - which security preset each project is set to, and what MCP server entries, hook definitions and Allow-list rules sit alongside it. Then decide whether the tenant-side controls Google announced actually describe those installs. If a laptop is signed in personally, the admin console's audit log does not cover it, and the endpoint is the only place that record exists.

Ask AI about Anomity
ChatGPT Claude Perplexity Google AI Grok