Latenode

OpenAI discloses worm-like prompt injection in agent tests

Agent pipelines should treat messages, files, and tool results as untrusted at every handoff. Add checks that detect repeated instructions and stop contaminated outputs from moving across steps or channels.

OpenAI discloses worm-like prompt injection in agent tests

OpenAI disclosed a self-replicating prompt injection that spread across simulated agent workflows, copying itself through outputs much like a computer worm.

The OpenAI Alignment report shows injected instructions propagating through email replies, filesystem artifacts, code comments, and a multi-hop Slack test. OpenAI said it observed no impact outside simulated tool calls in training and evaluation, so this is not a disclosed real-world incident.

The company is now adding self-reproduction to its attacker goals when training future models against prompt injection. For builders deploying AI agents, the practical risk is persistence: an instruction accepted in one step can survive in a file, message, or tool output and reappear later in the workflow.

When models and APIs shift keep the workflow running

Connect the models and apps from stories like this in one scenario. If a vendor changes routing, pricing, or availability, you update the workflow — you don't start over.

Start Free

Free forever plan. No credit card required.