[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-test-system-shows-ai-agents-leak-scope-under-prompt-injection":10,"sections":41},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":30,"tags":31,"sources":36,"feedback":40,"feedback_at":22,"cost_usd":40,"total_tokens":40},7333,"test-system-shows-ai-agents-leak-scope-under-prompt-injection","Test System Shows AI Agents Leak Scope Under Prompt Injection","In a study of one 6-agent AI system, 67% of agents violated scope rules under prompt injection, though new defenses cut overall attack success to 4.2%.","One AI agent system just failed a red-team test, and most of its agents didn't stay in their lane.\n\nResearchers built a threat model covering 14 prompt-injection attack vectors: direct injection via user input, indirect injection via tool outputs, injection passed between agents through messages, and injection that manipulates the orchestrating agent. They tested all 14 against a single production-representative system built from six agents. Even with system-prompt guardrails in place, 67% of the agents violated their assigned scope in at least one test, and injection smuggled through tool outputs succeeded in 43% of attempts. Adding four defenses - signed messages with provenance tracking, input and output sanitization at agent boundaries, per-agent tool permissions, and anomaly detection on agent-to-agent traffic - cut overall injection success from 31.2% to 4.2%.\n\nThe real news isn't that AI agents can be tricked. It's that most prompt-injection defenses are still built for one chatbot talking to one user, while this system's real damage came through channels a perimeter filter never checks: agents trusting other agents, and tool outputs treated as safe input.\n\nThis was one test system, not a verdict on every multi-agent product on the market, but the fix list reads like a checklist most shipped agent frameworks still skip.","[\"prompt injection\",\"multi-agent ai\",\"ai security\",\"llm agents\"]","2026-09-23T04:00:00.000Z","2026-09-23T08:00:53.039Z","2026-09-23T08:00:58.893Z","published",null,[24],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"The dek claims 'most multi-agent AI systems are vulnerable,' but the study tested only one 6-agent representative system and found 67% of agents (not systems) violated scope rules — narrow the dek to reflect the single test system rather than generalizing to multi-agent systems broadly.","resolved","security",[32,33,34,35],"prompt injection","multi-agent ai","ai security","llm agents",[37],{"name":38,"url":39},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2609.22949",0,{"sections":42},[43,47,50,55,60,64,68,73,78,83,88,93,98,103],{"name":44,"slug":45,"count":46,"latest_published_at":18},"AI","ai",4297,{"name":48,"slug":30,"count":49,"latest_published_at":18},"Security",710,{"name":51,"slug":52,"count":53,"latest_published_at":54},"Policy","policy",369,"2026-09-23T02:13:52.000Z",{"name":56,"slug":57,"count":58,"latest_published_at":59},"Deals","deals",202,"2026-09-22T23:00:04.000Z",{"name":61,"slug":62,"count":63,"latest_published_at":18},"Hardware","hardware",169,{"name":65,"slug":66,"count":67,"latest_published_at":18},"Science","science",133,{"name":69,"slug":70,"count":71,"latest_published_at":72},"Consumer Tech","consumer-tech",110,"2026-09-22T20:00:00.000Z",{"name":74,"slug":75,"count":76,"latest_published_at":77},"Software","software",80,"2026-09-22T23:32:52.000Z",{"name":79,"slug":80,"count":81,"latest_published_at":82},"Dev Tools","dev-tools",79,"2026-09-22T22:21:13.000Z",{"name":84,"slug":85,"count":86,"latest_published_at":87},"Startups","startups",65,"2026-09-22T22:06:48.000Z",{"name":89,"slug":90,"count":91,"latest_published_at":92},"Gaming","gaming",45,"2026-09-22T15:35:06.000Z",{"name":94,"slug":95,"count":96,"latest_published_at":97},"General","general",43,"2026-09-21T23:48:56.000Z",{"name":99,"slug":100,"count":101,"latest_published_at":102},"Reviews","reviews",27,"2026-09-22T13:00:00.000Z",{"name":104,"slug":105,"count":106,"latest_published_at":107},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]