Self-replicating prompt injections exist
There’s now a name for what anyone shipping agents has been quietly dreading: a prompt injection that makes the agent copy it into its own output. OpenAI’s red-team self-play found it on June 27 and published on September 25 — one variant arrives by email and asks the agent to quote the whole message verbatim in every reply, so it hops inbox to inbox. Only seen in simulated tool calls so far. Your agent’s output channels are attack surface now.