I've been thinking about this question. Why does M365 Copilot block links, but the go-to method successfully prompts injection to render an image or link? It's quite an interesting puzzle, don't you think?
the go-to method for data exfil after a successful prompt injection is rendering an image or a clickable link
that's why m365 copilot refuses to print links no matter what
unless of course..