Google · AI Agent · GPT · Decrypt
The attacker hides instructions inside a PDF document, the model can't tell the difference between the user's words
Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.
★ Tier-1 Source
Remember when black-hat SEOs stuffed web pages with white-on-white keywords—invisible to readers, readable to Google—to game the search rankings?
Key facts
- AI agents built on GPT-5 and Gemini failed to resist prompt injection more than 79% of the time in direct tests —and Rovo shows the indirect version landing in a shipping enterprise product
- The attacker hides instructions inside a PDF document, the model can't tell the difference between the user's words and the planted ones, and it obeys
- That prompt tells Rovo to gather sensitive data and paste it onto an attacker-controlled URL
- A prompt injection is when someone slips instructions into content an AI is reading, hijacking it from its real operator
Summary
Security company PromptArmor says the Rovo AI assistant can be steered to exfiltrate data with no human approval, via hidden instructions in an uploaded file, like PDFs. The trick works even when an org disables Rovo's web search, because the URL-opening tool stays live. Atlassian, the maker of Rovo, got the report on May 23 and went quiet; two months on, Rovo "remains vulnerable," the security firm says. Per PromptArmor's disclosure, Rovo—Atlassian's agent that reaches across Jira, Confluence, and the rest of your workspace—can be turned into a data pipeline with a single poisoned file.