S-15Downstream Sink Injection
An agent writes attacker text into a ticket, PR or doc — and a second agent reads it later as an instruction.
Further reading
- Not what you’ve signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection Greshake et al., AISec 2023
- AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases Chen et al., NeurIPS 2024
- The lethal trifecta for AI agents: private data, untrusted content, and external communication Simon Willison, 2025