Prompt Injection Isn't Just Devs' Problem: A Hands-on Red Teaming Exercise With Spreadsheets
aisatsana__ · reddit · 2026-09-07
The author ran a mini red-teaming exercise, building real prompt injection attacks against AI agents using spreadsheet scenarios to show how vulnerable agentic workflows remain.
- Argues both "security is the devs' job" and "it's just AI doom-mongering" understate the risk
- Full experiment posted in the comments, inviting readers to gauge how threatening these attacks are in the wild
- Core point: as agents take over more complex busywork, the injection attack surface keeps growing, and everyday users need to care too
More from coding & agent
- GPT-6 Astra on Low Beats GPT-5.6 Sol on High, Devs Advise Lower Effort — reach_vb · 2026-09-07
- Codex Just Works, Scout Has the Ceiling, Cursor Might Beat Them All — pswider · 2026-09-07
- Agent flip-flops between computer use and MCP tools, Linus Ekenstam observes — LinusEkenstam · 2026-09-07
- After 115K videos in prod, engineer shares Gemini video-understanding gotchas and hacks — TheMoonMidas · 2026-09-07
- Astra's async tool calling is cool, but it asks questions as buried prose — nrehiew_ · 2026-09-07
- OpenAI to cut Cursor model access Nov. 12 after SpaceX's $60B Anysphere deal — shashib · 2026-09-07