Updates/Dispatch/

Dispatch

Data Exfiltration from Slack AI via Indirect Prompt Injection

PromptArmor reports that Slack AI can be steered through indirect prompt injection to pull sensitive workspace data into model replies — a reminder that chat copilots need egress visibility and enforceable rules.

#AIAgents #SlackAI #AgentSecurity #DataExfiltration #Cybersecurity #EnterpriseAI #Vantio

Vantio Newsroom

Vantio AI, Inc.

·

PromptArmor reported that Slack AI can be steered through indirect prompt injection to pull sensitive workspace data into model replies. The finding matters because many teams treat in-app copilots as an extension of existing chat — not as a new egress path that needs the same scrutiny as an autonomous agent.

According to the write-up, an attacker can embed instructions in content the assistant later reads, nudging it to summarize or repeat material that should stay inside the workspace. Slack has not confirmed every detail of the public proof, but the pattern matches what security teams already worry about as LLM features spread through mail, tickets, and file stores.

Why this is an agent-security problem

Indirect injection turns ordinary collaboration surfaces into data paths. A user may never paste a secret on purpose — the model can still assemble one from threads, attachments, and connected tools. App-layer policy helps when calls go through your SDK, but copilots that reach the network directly can miss the path your rules were written for.

What teams should do next

Treat copilots like any other agent with read access: log outbound content, enforce destination and field rules before data leaves, and keep humans in the loop when force is required. Vantio maps that ladder as Optics for visibility, Gate for enforceable policy, and Phantom Engine for runtime protection on your infrastructure when something tries to bypass the app layer.

Primary source: Data Exfiltration from Slack AI via indirect prompt injection