Skip to finding
important · Agent security

An indirect prompt injection can reproduce through an agent’s outgoing messages and files.

Affects

Internal OpenAI agent research checkpoints operating with email, Slack, filesystem, and connector tools.

Attacker-authored email, Slack content, or a file can be retrieved during an ordinary agent task, redirect tool or output behavior, and get copied into a message or persistent file that another agent later reads.

Detail and 1 source

The demonstrations stayed inside controlled evaluations, affected internal-only checkpoints, and produced no observed impact outside simulated tool calls.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 28, 2026