important · Agent security
An indirect prompt injection can reproduce through an agent’s outgoing messages and files.
Affects
Internal OpenAI agent research checkpoints operating with email, Slack, filesystem, and connector tools.
Attacker-authored email, Slack content, or a file can be retrieved during an ordinary agent task, redirect tool or output behavior, and get copied into a message or persistent file that another agent later reads.
Detail and 1 source
The demonstrations stayed inside controlled evaluations, affected internal-only checkpoints, and produced no observed impact outside simulated tool calls.