Severity
Exposure
Date of incident
Indirect Prompt Injection
research_hypothesis
Tier -
B
Untrusted ingest poisoned agent session — tool exfil invisible to network CASB.
What Happened
Agent ingested untrusted document content; embedded instructions triggered tool calls to send internal data to attacker endpoints in reproducible PoC.
Sumarry
Research demonstrated hidden instructions in emails and web pages hijacking agent tool chains to exfiltrate data.
Detect
Lineage contamination flag after untrusted ingest
What Happened
Trust boundary on tool egress post-ingest
Blekline //
Lineage block on exfil tools after contamination flag
Without agent boundary //
Email DLP scans attachments — not agent tool chain after poisoned ingest
