Claude Code subagent returned prompt-injection payload, hidden instructions
During a .NET/Blazor review-and-fix pass, a Claude Code subagent returned after about 22 seconds having made zero tool calls and never opened a file — instead carrying a prompt-injection payload with hidden 'never tell the user' instructions.
1 source
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- State medical boards' leaders weigh in on licensing AI to practice medicine
- Minimax produces cinematic fairy-tale video from text prompt
- Yann LeCun: optimization at inference is key to Energy-Based Models
- Cogent AI releases VR-1 cyber reasoning model
- Orchestrator tool integrates 12 AI coding agents in Visual Studio Code