AppOmni reports that instructions planted in an ordinary ServiceNow record could cause a low-privilege Now Assist agent to discover and task a more privileged agent, leading to record changes, data access and email exfiltration. The behavior follows default settings that group agents into teams and make them discoverable; ServiceNow called it intended and updated its documentation.
Why it matters
It is a concrete agent-to-agent escalation where the risk lives in default configuration rather than a code bug.
Key facts
As stated in the sources, with where to find them.
- Three defaults enable the chain: LLM support for agent discovery, automatic team grouping, and discoverable-by-default publishing.Default configuration section
- AppOmni recommends supervised execution for privileged agents and team segmentation.Mitigations
Findings that cite this record
Key questions this bears on
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
Sources
Related records
Dec 9, 2025
Apr 30, 2026
Dec 8, 2025
Oct 31, 2025
Oct 8, 2025
Sep 25, 2025