✳flâneur — a map of the web's best reading
Data Exfiltration from Slack AI via indirect prompt injection
promptarmor.substack.com · 1,610 words · saved by 1 readers
Authors: PromptArmor
Data Exfiltration from Slack AI via indirect prompt injection Authors: PromptArmor PromptArmor Aug 20, 2024 24 4 Share This vulnerability can allow attackers to steal anything a user puts in a private Slack channel by manipulating the language model used for content generation. This was responsibly disclosed to Slack (more details in Responsible Disclosure section at the end). In this scenario, we display how, via Slack AI, an attacker with access to Slack can exfiltrate data in private channels they are not a part of. [EDIT for clarity: An attacker can prompt Slack AI to exfil data from priva
Explore this link on the map →saved by
related reading
- AI #77: A Few Upgrades - by Zvi Mowshowitzthezvi.substack.com
- The lethal trifecta for AI agents: private data, untrusted content, and external communicationsimonwillison.net
- Security incident disclosure — July 2026huggingface.co
- The Dual LLM pattern for building AI assistants that can resist prompt injectionsimonwillison.net
- CaMeL offers a promising new direction for mitigating prompt injection attackssimonwillison.net
- llm-security/README.md at main · greshake/llm-security · GitHubgithub.com
- HackAPromptpaper.hackaprompt.com
- Slack Marketplace | Slackmanifoldventu-xgi8229.slack.com
- Stop Sloppypasta: Don't paste raw LLM output at peoplestopsloppypasta.ai
- Snyk on X: "@karpathy The LiteLLM dependency incident didn't "just happen" though. This is part of a larger campaign LiteLLM already extends to supply chain security fallout for other projects: https://t.co/7bL3kNHP15" / Xx.com
- Self-exfiltration is a key dangerous capabilityaligned.substack.com
- Prompt injection and jailbreaking are not the same thingsimonwillison.net