Skip to content
Search
paperJune 2026Unreviewed

Assessing Automated Prompt Injection Attacks in Agentic Environments

David Hofer, Edoardo Debenedetti, Florian Tramèr

Abstract

Indirect prompt injection poses a critical threat to LLM agents that interact with untrusted external data, yet automated attack methods--proven effective for jailbreaking--remain underexplored in realistic agentic settings. We present a comprehensive empirical evaluation of automated prompt injection attacks against LLM agents, adapting both white-box (GCG) and black-box (TAP) methods to the agentic setting within the AgentDojo framework. We evaluate across 80 task pairs spanning four domains a

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection
  • AML.T0054LLM Jailbreak

Suggested from the entry's categories.

Cite

@misc{hofer2026assessing,
  title = {{Assessing Automated Prompt Injection Attacks in Agentic Environments}},
  author = {David Hofer and Edoardo Debenedetti and Florian Tramèr},
  year = {2026},
  month = jun,
  eprint = {2606.10525},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2606.10525}
}