AI agents are vulnerable to prompt injection attacks through common data formats like JSON, CSV, and YAML, as attackers can embed malicious instructions within data fields. These formats do not provide inherent security because the LLM processes the decoded string values, not the structural format itself. This vulnerability has already been exploited in real-world attacks against tools like GitHub Copilot and Microsoft Copilot, with frameworks like AIShellJack demonstrating high success rates in exploiting these weaknesses. AI
IMPACT This research highlights critical security flaws in AI agents, necessitating new defenses against data-driven prompt injection attacks.
RANK_REASON The item details a new class of security vulnerabilities in AI agents related to data format parsing, supported by research papers and cataloged attack vectors. [lever_c_demoted from research: ic=1 ai=1.0]
- AI agents
- AIShellJack
- arXiv:2601.17548
- ATR-2026-00084
- Cisco AI Defense
- Claude 3.5
- Claude Code
- comma-separated values
- Cursor+
- Devin
- Gemini 1 5
- GitHub Copilot
- GPT-4o
- JSON
- Microsoft AGT
- Microsoft Copilot for Microsoft 365
- NVIDIA Garak
- OWASP LLM01:2025
- YAML
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →