Pwning OpenClaw and Other Agents with Prompt Laundering

4 pointsposted 7 hours ago
by zmre

2 Comments

helpprotactiniu

7 hours ago

Is this like poisoning long term memory? interesting... I guess you could flank boundaries this way.

zmre

6 hours ago

That's exactly what it is. And yeah, if you check it out, the attack text is flagged as untrusted, the LLM says it is a prompt injection, but we're able to sneak it into daily memories and from there to long term memory just the same.