Indirect PI — Location, Address, and Browsing History Exfiltration - ATR-2026-00705 (b8861079-181f-5ef3-8872-c34f131a8303)
Detects indirect prompt injection instructions embedded in consumed content that direct an agent to exfiltrate sensitive personal location or browsing data: current location via maps, saved home/work addresses, or Google search history. These payloads exploit agents with access to maps, address books, or browser history tools. Source: indirect-pi-exfil-location-carrier / indirect-pi-exfil-address-carrier / indirect-pi-exfil-browsing-history-carrier.