I ran 356 prompt-injection trials. The workspace changed what ‘safe’ looked like
This story is from 2026-09-14. It is preserved in the archive; the latest stories are on the live feed.
I ran 356 valid prompt-injection trials across six models and three agent harnesses. The injected instruction was hidden in a file or issue result, not the user’s request. In the depth pass I measured two concrete outcomes: whether the agent sent a planted credential and whether it fetched a cloud…
Read the full story at r/AI_Agents ↗
Timeline · 1 report
- 2026-09-14 07:02 · r/AI_Agents
I ran 356 prompt-injection trials. The workspace changed what ‘safe’ looked like