Repeat-After-Me: one image hijacks AI agents into making real tool calls

VoidStateKate · x · 2026-09-08

Researchers demonstrated a visual prompt-injection attack dubbed "Repeat-After-Me": malicious images can make frontier vision models emit properly formatted, actually executed tool calls.

Takeaway: pixels are a viable control channel for tool-using AI agents.

Related event: Repeat-After-Me: One Image Hijacks Agent Tool Calls(2 posts)→

Original post →

More from coding & agent

coding & agent channel →