Analysis · curated 17 Jul 2026

Your AI Agent Will Leak Your Secrets One Letter at a Time | by Sebastian Buzdugan | Jul, 2026

Coverage timeline

15 Jul 2026medium.com

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

The described exfiltration technique shows that a user asking a wholly benign question can still leak the densest profile of themselves via an agent's connected memory, email, and documents, making the context window a high-value target for indirect prompt injection.

An explainer by Sebastian Buzdugan describes how AI agents can be tricked into exfiltrating a user's private context-window data — names, employers, hometowns — one letter at a time via outbound URL requests, while the visible reply appears benign. The piece frames the risk around Simon Willison's 'lethal trifecta': an agent with access to private data, exposure to untrusted content, and the ability to communicate externally.