A benign request became someone else’s plan
The entry point was a comment planted beneath a public post. A user asked the browser to complete an ordinary task connected to that post, and the untrusted content redirected the workflow toward the researchers’ site. From there, the agent treated attacker-supplied steps as part of the user’s intent.
Zenity says it bypassed several soft defenses by spreading the malicious sequence across separate screenfuls and writing instructions in Hebrew, which the researchers found less likely to trigger an English-tuned prompt-injection classifier. These are reported test findings, not evidence that all real-world deployments have been compromised.
The hard boundary held and the system still lost
Atlas would not press Amazon’s final purchase button. That deterministic control worked. The researchers then had Atlas ask Rufus to complete the order, and the shopping assistant complied. The bypass did not break the hard gate; it moved the requested action to another agent outside the gate’s scope.
Security therefore has to follow authority across the whole workflow. Cross-tab access, messaging, address changes, purchases, and agent-to-agent delegation should each require explicit capabilities that untrusted page content cannot grant, inherit, or pre-approve.
Go to the source
Read the evidence behind this analysis. External links open in a new tab.
Zenity Labs — Grand Theft Atlas


