An injected image overwrote TOOLS.md in a default OpenClaw Discord deployment where text injection failed
Repeat-After-Me is a black-box adaptive visual prompt injection that reaches attack success rates above 80% on Qwen3.6-27B and 47% on GPT-5.5 under a realistic setting where the benign user prompt is unrelated to the injected task and does not authorize it. Injections optimized on one surrogate retain 43-46% of their success on two commercial victims, and the authors demonstrate a real OpenClaw Discord deployment where an untrusted user's minimally injected image overwrites TOOLS.md, opening the door to remote code execution and secret exfiltration. The critical detail for builders is that this works in cases where adaptive textual prompt injection fails, so text-only injection filters are not covering the image path.
↳ Follow the thread