@kodekloud: The Lethal Trifecta in AI Agents 🔓 The lethal trifecta is Simon Willison's name for an AI agent that has three things at once: access to private data, exposure to untrusted content, and a way to send data out. Put all three in one agent and a single prompt injection, a hidden instruction inside an email or GitHub issue, can get your private data sent straight to an attacker. LLMs follow instructions wherever they find them and can't reliably tell yours from the attacker's. Does your AI agent have all three right now? Tell us in the comments. #LethalTrifecta #PromptInjection #AIAgents #AISecurity #MCP #LLMSecurity #AgenticAI #GenerativeAI #LLM #Cybersecurity #AIEngineering #KodeKloud #DevOps
Should always get the agent to create a draft and wait for your approval!
2026-10-09 08:00:16
0
RimjobSteve :
there is not a very good chance it will follow those instructions. there is a very small chance it will, but that is still scary. I've tested this and was unable to embed instructions in search text with any of the new models.
2026-10-09 08:45:53
1
Fukin-serious :
What's the solution ?
2026-10-09 03:16:27
1
CimiChanga :
That is why intents were created.
2026-10-08 19:42:41
0
AMG :
Treat all external content as untrusted data
2026-10-08 05:06:46
5
justCodeCraft :
Never allow your agent to send out messages automatically, it should rather draft the response then wait for your approval
2026-10-07 21:39:41
10
Sanity Optional 💙 :
if I had an AI agent that could not understand an email body contains instructions, it's a shit agent and should not be used.
2026-10-08 10:38:03
0
Sempre Sempre :
just train your agent to not react to words like password, reset etc
2026-10-07 19:29:53
0
CVA Retail :
Only allow ai to draft replies and u send it after review.
2026-10-08 05:33:42
0
Євгеній Мураєв🇮🇷💪 :
To avoid this in general in any context i just ask claud to create a script to perform automations, so it’s 100% deterministic approach, so even auto-publishing to github issue would not be the problem in 100% of cases, since script does not think or inferencing, it just acts in a deterministic way!
2026-10-08 03:14:22
1
Westlove | Software Engineer :
What about adding a guard rail
2026-10-08 07:21:47
2
sallymusic :
the LLM should know it's not in instructions
2026-10-07 21:12:14
1
davidbrewer257 :
they are trained to generally ignore new instructions from tool responses however. not don't it's foolproof but makes it harder.
2026-10-08 10:39:17
0
Cheesehead :
Excellent explanation and example of this prompt injection security threat.
2026-10-08 11:26:44
0
Robert T.S. :
i understand prompt injection but the example is weak. most normal software/apps/etc have an expiration link, an MFA, reset happens on the client side... this will not work
2026-10-08 18:57:15
0
Mr Drakoola :
Ok so great explanation. Can you also recommend a solution? Outside of the not sending stuff. How can you truly protect against and still have it be usable. Would it locking it in to only a specific email that can be sent to
2026-10-08 17:21:08
0
Âlphá VrkÅ :
how about set guardrails or security scanning after a strict read only from the email then capable to isolate the email in categories such as from external, identify senders and others. from there do the security scanning since it is read only with filtering. maybe need detailed configuration to avoid the agent to read it as general user prompt.. I'm not sure but just as thought 💭💭🤔🤔.. 🤷🏻. never done it before.. haha 😂
2026-10-08 11:50:29
0
KyleH :
This is legitimate and some to be awwre of but we solved it.. my ai does not listen to prompts in my email.. I’ve tested it. And Who cares if it puts password reset info?… how often are you resetting your password? Those link expire after you use them..
2026-10-08 15:47:16
0
IT Mario :
😂😂😂
2026-10-08 20:10:44
0
To see more videos from user @kodekloud, please go to the Tikwm
homepage.