Documentation can contain malicious instructions for agents
…When AI models process content, they cannot reliably distinguish between data and system instructions. For the PoC, two poisoned documents were created, one for Plaid Link and one for Stripe Checkout, each…