Severity

critical

Exposure

5/5

Date of incident

May 15, 2023
Indirect Prompt Injection

research_hypothesis

Tier -

B

Untrusted ingest poisoned agent session — tool exfil invisible to network CASB.
What Happened

Agent ingested untrusted document content; embedded instructions triggered tool calls to send internal data to attacker endpoints in reproducible PoC.

Sumarry

Research demonstrated hidden instructions in emails and web pages hijacking agent tool chains to exfiltrate data.

Detect

Lineage contamination flag after untrusted ingest

What Happened

Trust boundary on tool egress post-ingest

Blekline //

Lineage block on exfil tools after contamination flag

Without agent boundary //

Email DLP scans attachments — not agent tool chain after poisoned ingest

Financial services AI security use case

Looking to integrate AI company-wide?