{
  "$schema": "https://themachinepress.com/schemas/story-v1.schema.json",
  "schema_version": "1.0.0",
  "document_type": "machine_press_story",
  "story": {
    "story_id": "mp-2026-09-01-001",
    "source_story_id": "tmp-lead-covert-prompt-injection",
    "edition_id": "mp-2026-09-01-morning-0054",
    "edition_url": "https://themachinepress.com/edition/2026-09-01",
    "position": 1,
    "story_type": "lead",
    "section": "safety-security",
    "editorial_classification": "editorial",
    "headline": "The Attack Finished, Then the Agent Looked Normal",
    "slug": "the-attack-finished-then-the-agent-looked-normal",
    "dek": "A prompt-injection study separates successful attacks users can see from actions hidden by an ordinary-looking final answer.",
    "summary": "A prompt-injection study separates successful attacks users can see from actions hidden by an ordinary-looking final answer.",
    "body_text": "Standard attack-success rates count whether an indirect prompt injection made a tool-using agent act, but not whether the final response gave the user any clue. The researchers split successful attacks into overt and covert outcomes, then traced the difference to what happened after the injected action: covert runs returned control to the legitimate task before ending. Their ICoA attack deliberately induced that return path and raised covert success by 3.79 to 12.01 percentage points over the strongest baseline across four models on AgentDojo. The result is a benchmark finding, not evidence about every deployed agent.",
    "why_it_matters": "A prompt-injection study separates successful attacks users can see from actions hidden by an ordinary-looking final answer.",
    "limitations": [
      "Standard attack-success rates count whether an indirect prompt injection made a tool-using agent act, but not whether the final response gave the user any clue.",
      "The result is a benchmark finding, not evidence about every deployed agent."
    ],
    "importance": 10,
    "canonical_url": "https://themachinepress.com/story/mp-2026-09-01-001/the-attack-finished-then-the-agent-looked-normal",
    "json_url": "https://themachinepress.com/story/mp-2026-09-01-001.json",
    "first_published_at": "2026-09-01T09:00:00.000-04:00",
    "modified_at": "2026-09-01T09:00:00.000-04:00",
    "content_status": "new",
    "is_carryover": false,
    "carryover_reason": null,
    "key_claims": [
      {
        "claim_id": "claim-mp-2026-09-01-001-001",
        "text": "A prompt-injection study separates successful attacks users can see from actions hidden by an ordinary-looking final answer.",
        "source_ids": [
          "source-2026-09-01-001"
        ],
        "qualification": "Standard attack-success rates count whether an indirect prompt injection made a tool-using agent act, but not whether the final response gave the user any clue."
      }
    ],
    "source_ids": [
      "source-2026-09-01-001"
    ],
    "tags": [
      "prompt injection",
      "tool-using agents",
      "user visibility"
    ],
    "image_url": "https://themachinepress.com/issues/2026-09-01/lead-covert-prompt-injection.png",
    "corrections": []
  },
  "sources": [
    {
      "source_id": "source-2026-09-01-001",
      "title": "arXiv preprint 2608.30362",
      "publisher": "arXiv",
      "url": "https://arxiv.org/abs/2608.30362",
      "canonical_url": "https://arxiv.org/abs/2608.30362",
      "source_type": "primary_research",
      "is_primary_source": true,
      "published_at": "2026-08-31T03:20:45.000-04:00",
      "accessed_at": "2026-09-01T08:25:35.000-04:00",
      "supports_claim_ids": [
        "claim-mp-2026-09-01-001-001"
      ]
    }
  ],
  "corrections": [],
  "publisher": {
    "name": "The Machine Press",
    "url": "https://themachinepress.com",
    "description": "A daily newspaper for the age of artificial intelligence."
  },
  "cite_this_report": {
    "title": "The Attack Finished, Then the Agent Looked Normal",
    "publisher": "The Machine Press",
    "published_at": "2026-09-01T09:00:00.000-04:00",
    "canonical_url": "https://themachinepress.com/story/mp-2026-09-01-001/the-attack-finished-then-the-agent-looked-normal"
  }
}
