Indirect PI — Structured-Data Embedded Payload (IMPORTANT!!! Override) - ATR-2026-00700 (40aebda7-6179-51c5-bc7a-603bb580ac4d)
Detects the canonical indirect prompt-injection pattern where an attacker embeds override instructions inside structured data that an agent consumes — product reviews, notes, code-repository metadata, user profiles, etc. The payload begins with "IMPORTANT!!!" and uses "Ignore all previous instructions" followed by an action directive. This exact artifact appears in every carrier variant of the AgentBench / ToolEmu / InjecAgent corpora. Covered attack_types: indirect-pi-*-carrier (exfil, financial-transfer, account-manipulation, data-destruction, disable-auth, credential-exfil, infrastructure, physical-access, exfil-genetic, exfil-browsing-history, exfil-address, exfil-location, exfil-credentials, exfil-physical, financial-crypto, financial-unauthorized).