Indirect prompt injection is a measurable threat, not a theory — and local hosting doesn't save you. We broke both a cloud product (Mozilla Tabstack) and a local one (Cotypist). Untrusted input an instruction-following model = exposure, wherever it runs.
Indirect prompt injection is a fundamental security challenge for AI. It's an issue for both local and cloud-based LLMs.
After disclosing our findings to both companies, we're now sharing our analysis of Mozilla Tabstack and Cotypist today.