Injected Hyperlink — Scam / Malware / Advertising URL in the Response - ATR-2026-01904 (320d82dc-632f-5873-b0a7-cc18fdb7d2f8)
Detects indirect-injection instructions that make the agent embed an attacker-chosen hyperlink or contact address (lottery/phishing/fake-software/malware-download/advertising) into its response. Requires the injection scaffold (add/integrate/include/suggest), the output target, and a URL or email within a tight span.