PromptSpy: A Framework for Simulating Indirect Prompt Injection Across Autonomous Email Pipelines - Cybersecurity Conference

PromptSpy: A Framework for Simulating Indirect Prompt Injection Across Autonomous Email Pipelines

Email remains the backbone of communication at every level, from individuals to large enterprises, and AI adoption is reshaping how that communication happens. Rather than manually composing and replying to messages, both companies and individuals increasingly rely on AI assistants to handle the work such as drafting emails, summarizing conversations, prioritizing messages, and generating replies on their behalf.

As enterprise email workflows evolve into interconnected, multi-agent AI systems, we introduce a new attack surface that extends beyond traditional phishing and single-model prompt injection. This paper investigates a new emerging attack surface created by these AI-assisted workflows. We call this technique PromptSpy.

The attack framework demonstrates several forms of indirect prompt injections in email including “hidden HTML”, “invisible Unicode characters”, “metadata-based instructions”, and “forged role delimiters” that can influence downstream AI processing while remaining transparent to human recipients. The framework further compares protected and simulated processing paths to examine the effectiveness of defensive mechanisms such as content sanitization, provenance validation, and context isolation.

PromptSpy encourages a broader view of AI security by shifting attention from individual prompts to the interactions between autonomous agents. As AI assistants become integral to enterprise communication, securing the orchestration pipeline will be as important as securing the underlying language models.

By the end of this talk, attendees will gain an understanding of how multi-agent AI email systems introduce security risks beyond traditional phishing and single-model prompt injection. They will learn how indirect prompt injection can influence downstream AI assistants, explore practical defensive techniques for securing AI-native email workflows, and gain actionable insights into protecting enterprise AI orchestration pipelines against emerging AI-to-AI attack scenarios.

Prashant Kumar, Forcepoint Software India Pvt. Ltd

Prashant Kumar is a Senior Security Researcher with 8+ years of experience in cybersecurity, specializing in the research and analysis of malicious URLs, emails, and files. His work focuses on identifying and mitigating emerging and in-the-wild cyber threats, including sophisticated phishing, social engineering and malicious campaigns.

He also researches AI-assisted phishing and AI-driven malicious campaigns, exploring how threat actors are leveraging AI to evolve their attack techniques and how security teams can detect and defend against them.

Beyond threat research, Prashant actively shares his findings and technical insights through research blogs published on the Forcepoint website. He is also a conference speaker and recently presented his research at CSA XCON 2026.