An agent that browses, reads email, summarises files or calls tools takes in text from sources nobody vetted. Any of it can contain instructions — sometimes invisible to people, through white text, markup or special characters.
Because the user never sees the payload, indirect injection can trigger zero-click: the attack runs when the agent does its normal job.
+Why it matters
It turns every data source an agent can read into a way to control it.
+How Intertrace handles it
Retrieved content and tool results pass through the same inspection as prompts, with a separate view of what a person sees and what the model sees. Hidden instructions are a structural floor.
+Keep reading
+ The AI watching your AI
See it on your own traffic.
Book a 30-minute risk assessment, or open the Simulation Lab and try it now.