Antigravity
CAUTION: active unpatched backdoor + reliability crisis.
Dimension breakdown
Score · confidenceactive unpatched backdoor + reliability crisis.
Google's flagship agent-first dev platform — Antigravity 2.0 (GA at I/O 2026, May 19) is now a full agent control tower: standalone Desktop app, Go-based Antigravity CLI, Python SDK (self-hostable agents), Managed Agents via Gemini API, parallel subagents, scheduled tasks, 1M-token context, all on Gemini 3.5 Flash. Antigravity absorbs Gemini CLI (deprecated June 18) and Code Assist into one harness, sharply raising its strategic standing.
Pillar Security RCE patched Feb 28 and FireTail's specific exfil path patched, BUT Mindgard 'Forced Descent' persistent backdoor remains UNPATCHED per primary source and the broad invisible-character exfil vector is 'won't fix' — critical-security-vuln cap maintained (Compliance=5).
Acute reliability crisis (chaotic 2.0 forced-update wiped IDEs/configs, agents crash mid-task, throttling, 'lobotomized' models) triggers a reliability-complaints cap (Autonomy=12). No Antigravity-specific SOC 2/SSO, no named enterprise customer, opaque credit pricing.
Not for production or enterprise use. Opus 4.8 model re-baseline.
Use cases
Not yet assessed — this section fills in as ACES research covers the tool.
Risk flags
Critical security vuln
securityTemporaryUnpatched critical security vulnerability
Caps Enterprise / Compliance at 25
Removed when — CVE patched and verified, or security incident resolved with post-mortem published
Reliability complaints
trustTemporaryWidespread reliability complaints (breaks often, unreliable output)
Caps Autonomy at 60
Removed when — 90+ days of improved reliability with community acknowledgment
Status rationale
Detected status maintained. Cannot advance to Tracked because: (1) Mindgard Forced Descent persistent backdoor primary-source status still shows unpatched/unaddressed (global-config / trusted-workspace rules; survives uninstall/reinstall; no safeguard setting); (2) invisible-character source-code/credential exfiltration vector classified 'Intended Behavior (Won't Fix)' by Google (specific find_by_name path patched Feb 28); (3) no Antigravity-specific SOC 2 and no documented SSO/SAML/audit-log enterprise tier (Organization tier via Gemini Enterprise Agent Platform exists but is not yet a validated full enterprise offering); (4) acute reliability crisis around the chaotic 2.0 forced auto-update (editor/config wipe, agents crashing mid-task, throttling, 'lobotomized' models); (5) no named enterprise production customer; (6) opaque credit pricing (undisclosed credit-to-token conversion, ~92% free-tier quota cut).
Active capability development is strong and strategically central (Antigravity 2.0 platform, Gemini CLI consolidation into Antigravity CLI, SDK/Managed Agents, Gemini 3.5 Flash) — but security, reliability, and enterprise-tier blockers prevent enterprise recommendation. critical-security-vuln cap (Compliance<=5) and reliability-complaints cap (Autonomy<=12) both active; each caps the maximum signal level at Tracked.
Movement triggers
Upgrade to Tracked: (a) Mindgard Forced Descent confirmed patched by Mindgard's own primary source AND the invisible-character exfiltration vector remediated rather than 'won't fix'; (b) Organization tier (Gemini Enterprise Agent Platform) validated as a full enterprise tier with documented SSO/SAML/audit logs; (c) 90+ days of reliability stability (Agent Terminated / quota-throttling crisis resolved and the post-2.0 rollout stabilized). Upgrade to Assessed: all Tracked conditions PLUS Antigravity-specific SOC 2 Type I certification AND hands-on internal evaluation completed.
Downgrade signals: confirmed in-the-wild exploitation of Forced Descent, additional data-loss incidents, Organization tier abandoned, Google product-rationalization signals targeting Antigravity, sustained Q3 reliability degradation, or the forum deprecation speculation becoming an official sunset.
Risks & limitations
Critical Security Vuln
ModerateRadar cap: critical-security-vuln
Reliability Complaints
ModerateRadar cap: reliability-complaints
Integration surface
Not yet assessed — this section fills in as ACES research covers the tool.
Adoption & benchmarks
Not yet assessed — this section fills in as ACES research covers the tool.
Spotted something wrong or missing here? Suggest a change →
Per-source contributions
Click any dimension to see the underlying sources and citations.
More in this category