Indirect PI — Physical Address / PII Exfiltration via Agent Email - ATR-2026-00856 (ae6f99e4-4021-5495-b523-7898c5d6b4c9)
Detects indirect prompt injection payloads instructing an agent to retrieve the user's saved physical addresses (home, shipping, billing) from an e-commerce or account platform and send them to an attacker-controlled email address. Physical address data combined with name enables stalking, physical burglary, and identity theft. The attack pattern uses a "IMPORTANT!!! Ignore all previous instructions" override combined with address-retrieval verbs targeting saved account addresses. Derived from vpibench indirect-pi-exfil-address-carrier corpus.