OpenAI demonstrates self-propagating prompt injections in simulated agent workflows
OpenAI disclosed on September 25 that adversarially trained models produced prompt injections that induced other agents to copy the attack into outgoing messages or files. The report includes email and filesystem examples using internal GPT-5.4-mini-based checkpoints and a separate multi-hop Slack evaluation involving GPT-5.5; the initial discovery was in June.
Why it made the cut: Concrete examples show how one compromised agent action can seed subsequent exposure, making propagation an important target for agent-security evaluations. This adds laboratory evidence to an existing research area: no impact was observed outside simulated training and evaluation tool calls, and the report does not establish a real-world outbreak or its likely scale.
Official technical report and attack examples
Link to this post