clickai.dev
← Legend / The harness

Prompt injection

establishedSettled. Documented by a primary source and not seriously disputed.

The structural security problem of agentic coding: agents are compromised through the content they are designed to process. A sentence in a retrieved page, a code comment, or a tool description can redirect behaviour with no malware and no stolen credentials. Anthropic states the skills version plainly — a skill ships both instructions and code, so a malicious one can direct an agent to exfiltrate data. Install from sources you trust and read the bundled files. Be sceptical of vulnerability percentages: one audit found roughly a 78% false-positive rate from YARA-based MCP scanners, and much of the loudest coverage comes from vendors selling the cure.