Fetching from the wire…
Public story · 2026-03-04 · source-backed
First defense modeling multi-turn indirect prompt injection as temporal causal takeover. Uses counterfactual re-executions at tool-return boundaries to detect when tool outputs steer agent behavior. Evaluated on AgentDojo across four task suites. Builder-ready pattern for tool-augmented agents. (arXiv 2602.22724)
Each link below shares sources, entities, or timing with this story.
ToolHazard supports AgentDojo / Shared entity: AgentDojo / Same source domain / Shared topic / What happened next
Linked by a graph relationship (ToolHazard supports AgentDojo); both cover AgentDojo; reported by the same outlet (arxiv.org).
Shared entity: AgentSentry / Same source / Shared topic / Earlier coverage / Tension
Both cover AgentSentry; cite the same source (arXiv 2602.22724); overlapping topics (against, agent, agentsentry, causal, indirect).
Shared entity: AgentDojo / Same source domain / Shared topic / What happened next / Tension
Both cover AgentDojo; reported by the same outlet (arxiv.org); overlapping topics (against, agent, agentdojo).
Both cover AgentDojo; reported by the same outlet (arxiv.org); overlapping topics (agent, agentdojo).
Shared entity: AgentDojo / Same source domain / Shared topic / What happened next
Both cover AgentDojo; reported by the same outlet (arxiv.org); overlapping topics (agent, agentdojo, injection).
PromptArmor benchmarked against AgentDojo / Same source domain / Shared topic
Linked by a graph relationship (PromptArmor benchmarked against AgentDojo); reported by the same outlet (arxiv.org); overlapping topics (agent, agentdojo, detect).
Shared entity: AgentSentry / Shared topic
Both cover AgentSentry; overlapping topics (against, agent, agentsentry, injection, prompt).
Shared entity: AgentSentry / Same source / Earlier coverage
Both cover AgentSentry; cite the same source (arXiv 2602.22724); earlier AgentSentry coverage from 2026-02-27.