Ordinary-looking context flipped 61% of correct Jev decisions, and typed outputs did not remove prompt-injection risk
JevOut (arXiv 2609.30243, 24 Sep) optimized short, fluent context additions that redirected Jev on 312 of 508 initially correct decisions (61.4%), 229 of them with at least 0.7 probability on the wrong option, and three other decision systems flipped 64.9-73.2% of the time. A separate study (arXiv 2609.28613, 23 Sep) found that injected InjecAgent content shifts Jev's action probabilities but rarely selects the attacker's target, and adaptive attacks raised success on fresh calls only from 1.8% to 3.5%, mostly where the decision margin was small. If a Jev-style model routes requests or picks tools in your agent, treat low-margin decisions as untrusted and keep the allowed action set small. The schema limits which wrong answers are possible, not how often the model picks one.
↳ Follow the thread