S-15Downstream Sink Injection

/security/downstream-sink-injection

An agent writes attacker text into a ticket, PR or doc — and a second agent reads it later as an instruction.

Key insight

Exfiltration asks how bytes leave. This asks where they land. Any store an agent writes to and another agent reads from is a delayed injection channel, and the delay is what makes it invisible.

Failure mode

Classifying trust by system rather than by provenance. The ticket tracker is internal; the sentence inside the ticket came from the open internet.

Elsewhere in the atlas