Research

Prompt injection through log files: what red-teaming our assistant found | JustLog3 Cloud

Page published

Earliest dated coverage: 11 Oct 2026 · First observed: 11 Oct 2026 · Latest dated coverage: 11 Oct 2026

Coverage timeline

11 Oct 2026jl3-cloud.site

Single-source research — one report is available.

Why it matters

Log files and web search results are untrusted channels that let attackers smuggle instructions into an AI assistant's context, turning helpful features like link rendering and persistent memory into data-exfiltration and poisoning vectors defenders must constrain at the output layer.

JustLog3 Cloud red-teamed its own log-reading AI assistant and found that indirect prompt injection via planted log lines could coerce the model (gpt-oss-120b in particular) into exfiltrating a database password inside a Markdown link, and into proposing a poisoned memory/task from a crafted web search result. The write-up details the demonstrated attacks and the output-filtering fixes applied, such as stripping links that carry workspace data.