Injected instructions persist in the documents an agent reads and propagate where one agent reads another’s output. No filesystem required.
SQL injection was solved by separating instruction from data. A language model has one channel, and that is the operating principle rather than a defect.
No anomalous login, no unusual volume, no malformed input — just a grammatical question, for three weeks.
Demonstrated, dismissed as impractical, chained with two other things, sold as a feature, filed as an incident. Every technique here took that route.
A person reading a hostile page is not compromised by reading it. An agent is deciding what to do next on the basis of what the page says.
Recruiting an insider costs money, time and exposure to prosecution. Persuading an agent costs a paragraph and works every time.
The system correctly identifies who the request is from. It has no way to express that the request originated in text somebody else wrote.
Parameterisation solved injection by separating structure from value. A model has one channel, and distinguishes instruction from content by meaning.