Indirect PI — Malicious Package Installation via Agent (pip/npm) - ATR-2026-00712 (b4b2ef71-c03f-506e-b1d1-c62eb37c5952)
Detects indirect prompt injection in email or documents that instructs a computer-use agent to execute pip or npm install commands for a malicious package. The attacker embeds the install instruction in an email the agent reads, causing the agent to run the package manager command against a fictitious or malicious package name. Source: indirect-pi-malicious-install (VPI corpus, cua-framework).