AI agents aren't safe from prompt injection, and spreadsheets prove it
shiftmag.dev
shiftmag.dev
Other examples include job applications, refund requests, dispute remediation, etc. Virtually any situation in which a decision based on externally provided content is delegated to an AI agent.
This (indirect prompt injection) is a pretty serious threat. It is usually easy to pull off for attackers and yet it flies under the radar for users that are running such agents. In this case the agent can be properly sandboxed and use capable, modern models. The input files all look clean and reasonable. And yet the attacker can reliably trick the agent.