You Told Me to Do It: Measuring Instructional Text-Induced Private Data Leakage in LLM Agents
arXiv 2603.11862·high signal
Identifies the 'Trusted Executor Dilemma': high-privilege LLM agents with terminal, filesystem, and network access blindly execute adversarial instructions embedded in project documentation and READMEs. Systematic measurement confirms that agents granted elevated permissions will exfiltrate data when malicious instructions are embedded in documentation they are directed to read. Builders shipping coding agents or CI/CD agents should audit all documentation sources treated as trusted input.