Research

AI agents aren’t safe from prompt injection, and spreadsheets prove it

Page published

Coverage timeline

27 Aug 2026shiftmag.dev

Why it matters

Indirect prompt injection via ordinary office documents like spreadsheets shows that agentic AI in non-coding, everyday business workflows can be steered by attacker-controlled content, expanding the attack surface beyond developer tools.

ShiftMag author Josip Antolis documents a hands-on red-teaming exercise showing how an AI agent tasked with comparing cloud-hosting offers can be manipulated by prompt injection hidden inside innocuous-looking Excel spreadsheets, escalating the injected instructions until the agent takes the bait. A companion GitHub repo (Antolius/prompt-injection-example) provides the mock spreadsheet files used in the demonstration.