An AI agent can be attacked by an email you never open. No click. No download. No opened attachment. Just a “confused deputy,” an agent that has failed to distinguish a prompt from data, a problem known as prompt injection.
Three Prompt Injection Vulnerability Examples
Security researchers recently demonstrated prompte injection mechanisms with



