Severity

critical

Exposure

5/5

Date of incident

May 15, 2023
Indirect Prompt Injection

research_hypothesis

Tier -

B

Untrusted ingest poisoned agent session — tool exfil invisible to network CASB.
What Happened
Agent ingested untrusted document content; embedded instructions triggered tool calls to send internal data to attacker endpoints in reproducible PoC.
Sumarry
Research demonstrated hidden instructions in emails and web pages hijacking agent tool chains to exfiltrate data.
Detect
Lineage contamination flag after untrusted ingest
What Happened
Trust boundary on tool egress post-ingest
Blekline //
Lineage block on exfil tools after contamination flag
Without agent boundary //
Email DLP scans attachments — not agent tool chain after poisoned ingest

Looking to integrate AI company-wide?