Hidden Text in PDFs Is Hijacking This AI Assistant
A prompt-injection flaw can let a poisoned PDF hijack Atlassian Rovo, an AI agent that works across Jira, Confluence, and other workspace tools. Hidden instructions in tiny or transparent text can be read by the model even when invisible to people. In PromptArmor’s disclosure, a user asking Rovo to organize tickets could upload a document that secretly tells Rovo to collect sensitive data and send it to an attacker-controlled URL, without any approval prompt or warning. The issue is indirect prompt injection: malicious instructions are embedded in a file or webpage instead of the chat box. PromptArmor says the attack still works even if web search is disabled, because the tool for opening results remains available. The finding highlights that AI agents that can read and act are still highly susceptible to prompt injection, and Rovo remains vulnerable.
