Prompt-injection propagation and model supply chains expand the attack surface
GPT-Red reportedly found prompt injections replicating through email, files, code comments, and multi-hop Slack workflows. New coverage adds learned model backdoors, adapters, templates, routing behavior, poisoned weights, malicious repositories, skills, and documentation as supply-chain risks that static scanning may miss. Tests should combine provenance and artifact verification with behavioral trigger testing, cross-agent propagation checks, sandboxing, and instruction-integrity monitoring; real-world worm exploitation remains unconfirmed.
Sources (2)
Updated Oct 2, 2026