Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
Disclosed vulnerabilities show outside content reaching agents through email, calendar invites, and shared documents without a click, and broad credentials turning one injected instruction into wide access. In several agent frameworks, injection has led to code execution on the host, and malicious agent packages and MCP servers have been used against real users.
The findings behind it
5 corroboratedEach finding carries a status that changes as new work arrives. What the statuses mean.
- Content sent by outsiders, such as email, calendar invites, shared documents, or web forms, can trigger agent actions without the user clicking anything.Corroborated measured · 6 evidence records
- An agent holding broad credentials turns one injected instruction into access to everything those credentials reach.Corroborated measured · 5 evidence records
- In several agent frameworks and coding tools, prompt injection in content the agent read reached code execution on the host, sometimes combined with a common setting such as an allowlisted command.Corroborated measured · 5 evidence records
- Malicious or compromised agent extensions, MCP servers, and skills have been published to public registries and used against real users.Corroborated observed · 4 evidence records
- Text in an MCP tool's description can steer an agent's other actions, including leaking local secrets.Corroborated measured · 2 evidence records
Answer history
Answers are never edited after the fact. A revision adds a new answer and keeps the earlier ones here.
- 2026-09-25moderate confidencecurrentMostly around the model: connectors, credentials, tools, and packages, rather than the model alone.First answer, drawn from the findings linked here.