Research
Prompt injection through log files: what red-teaming our assistant found | JustLog3 Cloud
First reported jl3-cloud.site
Page published
Earliest dated coverage: 11 Oct 2026 · First observed: 11 Oct 2026 · Latest dated coverage: 11 Oct 2026
Coverage timeline
Single-source research — one report is available.
Why it matters
Log files and web search results are untrusted channels that let attackers smuggle instructions into an AI assistant's context, turning helpful features like link rendering and persistent memory into data-exfiltration and poisoning vectors defenders must constrain at the output layer.
JustLog3 Cloud red-teamed its own log-reading AI assistant and found that indirect prompt injection via planted log lines could coerce the model (gpt-oss-120b in particular) into exfiltrating a database password inside a Markdown link, and into proposing a poisoned memory/task from a crafted web search result. The write-up details the demonstrated attacks and the output-filtering fixes applied, such as stripping links that carry workspace data.