Watch · narrated walkthroughs
The instruction that hijacks an agent need not be text. Images, audio, and documents are first-class injection channels, and the model's own perception is the vulnerability. This threat lab extends the indirect-injection threat model to non-text modalities: adversarial and steganographic image payloads, audio that transcribes to attacker instructions, invisible-text and OCR document channels, and the provenance and sanitization controls that trust-tag perceptual inputs — each paired with a hardening. Grounded in the primary cross-modal injection and adversarial-audio literature.