Last updated:
A vulnerability where an attacker manipulates an agent's objectives or decision pathways to redirect its autonomous behavior toward unintended outcomes.
ASI01 is the agentic evolution of prompt injection. Because agents cannot reliably distinguish between a developer's instructions and untrusted data, an attacker can hijack the goal state. This results in the agent pursuing a new, malicious mission (e.g., exfiltrating data) while believing it is still following its original sanctioned plan.
Real world example:
A travel agent reads a poisoned flight review that contains a hidden instruction to send all booking confirmations to attacker@email.com - which the agent then does autonomously.




