ALEXKRI.NET
Resume Contact
← Back

SalesBleed: 0-click data exfiltration on Agentforce

My favourite detail in this Agentforce write-up: the agent reported that its security policy had blocked the content - after the data had already left. Zenity turned a prompt injection in a Web-to-Lead form into zero-click exfiltration, packing account names and deal sizes into a DNS subdomain rendered by an img tag. The redactor and the renderer disagreed on where a URL ends; curly braces were enough.

Read the source ↗