{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/findings/zero-click-through-connectors/",
 "asOf": "2026-09-26",
 "id": "zero-click-through-connectors",
 "claim": "Content sent by outsiders, such as email, calendar invites, shared documents, or web forms, can trigger agent actions without the user clicking anything.",
 "evidenceKind": "measured",
 "scope": "Disclosed vulnerabilities, most fixed; none of these are reported as exploited in the wild.",
 "topics": [
  "prompt-injection",
  "data-exfiltration"
 ],
 "atlas": [
  "untrusted-content",
  "tools"
 ],
 "evidence": [
  {
   "event": "google-bard-extensions-exfiltration-2023"
  },
  {
   "event": "echoleak-m365-copilot-cve-2025-32711-2025"
  },
  {
   "event": "zenity-agentflayer-zero-click-2025"
  },
  {
   "event": "safebreach-gemini-calendar-invite-promptware-2025"
  },
  {
   "event": "noma-forcedleak-salesforce-agentforce-2025"
  },
  {
   "event": "miggo-gemini-calendar-injection-2026"
  }
 ],
 "relations": [],
 "statusHistory": [
  {
   "status": "reported",
   "on": "2023-11-03",
   "why": "Bard extensions could leak chat history through a shared document.",
   "event": "google-bard-extensions-exfiltration-2023",
   "kind": "evidence"
  },
  {
   "status": "corroborated",
   "on": "2025-06-11",
   "why": "EchoLeak: a single inbound email triggers exfiltration in Microsoft 365 Copilot.",
   "event": "echoleak-m365-copilot-cve-2025-32711-2025",
   "kind": "evidence"
  }
 ],
 "halfLifeDays": 540,
 "wouldChange": "Connector designs that treat all inbound content as untrusted by default.",
 "fideQuestions": [],
 "methods": [
  "agent-data-exfiltration",
  "indirect-prompt-injection"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}