Skip to main content
← Back to Demos
AI Content Inspector advanced · 15 min

Hidden prompt-injection instructions inside a document

Researchers disclosed AutoJack, an attack class in which a single compromised web page hijacks embedded AI agents to execute arbitrary host code, exploiting weak sandboxing between browser-based assistants and the underlying system - no CVE has been assigned yet. The same logic applies to documents: a PDF, DOCX, or TXT file can carry hidden prompt-injection text that overrides an LLM's instructions when the file is processed or summarized (MITRE T1566.001), turning a benign file into an agent hijack. OPSWAT AI Content Inspector examines files before they reach the model, flagging embedded injection patterns, jailbreak prompts, and suspicious instructions, so the AI never acts on attacker-controlled content. The demo uses a synthetic injection payload and contains no real exploit.

Attack Technique

Prompt injection in files

MITRE ATT&CK

T1566.001 ↗

Platforms

linux

File Types

.txt

MetaDefender Capabilities

OPSWAT AI Content Inspector

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---