Agent prompt injection is producing real compromise paths
The reported Manus incident shows an indirect prompt injection escalating through obfuscation to reverse-shell RCE and theft of connected-service credentials. The key developing issue is whether agent vendors can demonstrate robust sandboxing, authorization boundaries, token isolation, and meaningful pre-execution defenses rather than merely detecting malicious instructions after execution.
Sources (3)
Updated Sep 25, 2026