---
schema_version: "newruntime-topic-hub-v0.2"
type: "topic_hub"
stable_id: "topic_hub:prompt-injection"
slug: "prompt-injection"
title: "Prompt Injection - New Runtime"
description: "A New Runtime topic hub collecting signals, patterns, field notes, and public sources about prompt injection."
retrieval_nugget: "A New Runtime topic hub collecting signals, patterns, field notes, and public sources about prompt injection. Prompt Injection is tracked here as an evidence-linked topic, not as a static glossary entry. The page connects raw observations to pattern hypotheses, longer analysis, and public sources. Use it as the canonical landing page before drilling into individual records."
answer: ["Prompt Injection is tracked here as an evidence-linked topic, not as a static glossary entry.","The page connects raw observations to pattern hypotheses, longer analysis, and public sources.","Use it as the canonical landing page before drilling into individual records."]
search_intents: ["prompt injection","prompt injection AI agents","prompt injection software"]
status: "featured"
last_updated: "2026-07-21"
record_date: "2026-07-21"
date_kind: "last_updated"
counts: {"total":23,"signals":22,"patterns":0,"posts":1,"atlas":0,"sources":29}
routes: {"html":"https://newruntime.com/topics/prompt-injection/","markdown":"https://newruntime.com/topics/prompt-injection.md","json":"https://newruntime.com/topics/prompt-injection.json"}
source_urls: ["https://aitmpl.com/component/hook/dangerous-command-blocker","https://anthropic.com/engineering/claude-code-auto-mode","https://anthropic.com/glasswing","https://arxiv.org/abs/2607.06595","https://blog.cloudflare.com/moltworker-self-hosted-ai-agent","https://blog.lukaszolejnik.com/supply-chain-risk-of-agentic-ai-infecting-infrastructures-via-skill-worms","https://blog.palantir.com/securing-agents-in-production-agentic-runtime-1-5191a0715240","https://developers.googleblog.com/tailor-gemini-cli-to-your-workflow-with-hooks","https://developers.openai.com/cookbook/examples/agents_sdk/sandboxed-code-migration/sandboxed_code_migration_agent","https://docs.clawd.bot/gateway/security","https://docs.sprites.dev/","https://github.com/0x4m4/hexstrike-ai"]
top_sources: ["https://aitmpl.com/component/hook/dangerous-command-blocker","https://anthropic.com/engineering/claude-code-auto-mode","https://anthropic.com/glasswing","https://arxiv.org/abs/2607.06595","https://blog.cloudflare.com/moltworker-self-hosted-ai-agent","https://blog.lukaszolejnik.com/supply-chain-risk-of-agentic-ai-infecting-infrastructures-via-skill-worms","https://blog.palantir.com/securing-agents-in-production-agentic-runtime-1-5191a0715240","https://developers.googleblog.com/tailor-gemini-cli-to-your-workflow-with-hooks","https://developers.openai.com/cookbook/examples/agents_sdk/sandboxed-code-migration/sandboxed_code_migration_agent","https://docs.clawd.bot/gateway/security","https://docs.sprites.dev/","https://github.com/0x4m4/hexstrike-ai"]
---

# Prompt Injection - New Runtime

A New Runtime topic hub collecting signals, patterns, field notes, and public sources about prompt injection.

## Retrieval answer

A New Runtime topic hub collecting signals, patterns, field notes, and public sources about prompt injection. Prompt Injection is tracked here as an evidence-linked topic, not as a static glossary entry. The page connects raw observations to pattern hypotheses, longer analysis, and public sources. Use it as the canonical landing page before drilling into individual records.

## Patterns


## Field Notes

- [GhostWriter: One Email Can Poison Long-Term Agent Memory](https://newruntime.com/posts/ghostwriter-agent-memory-poisoning/): GhostWriter shows a new risk class for agent systems: malicious content can enter long-term memory and later activate as trusted context.

## Recent Raw Signals

- 2026-06-28: [Role confusion helps explain prompt injection](https://newruntime.com/signals/role-confusion-explains-prompt-injection/)
- 2026-04-23: [GitHub / TencentCloud/CubeSandbox: Agent Security Runtime Boundaries](https://newruntime.com/signals/github-tencentcloud-cubesandbox-agent-security-runtime-boundaries/)
- 2026-04-22: [Claude: Agent Security Runtime Boundaries](https://newruntime.com/signals/claude-agent-security-runtime-boundaries/)
- 2026-04-19: [Sandboxed Code Migration Agents (OpenAI cookbook)](https://newruntime.com/signals/sandboxed-code-migration-agents-openai-cookbook/)
- 2026-04-10: [Claude Mythos + Project Glasswing](https://newruntime.com/signals/claude-mythos-project-glasswing/)
- 2026-04-07: [GitHub / SafeAI-Lab-X/ClawKeeper: Agent Security Runtime Boundaries](https://newruntime.com/signals/github-safeai-lab-x-clawkeeper-agent-security-runtime-boundaries/)
- 2026-03-30: [Anthropic / Claude Code Auto Mode: Agent Security Runtime Boundaries](https://newruntime.com/signals/anthropic-claude-code-auto-mode-agent-security-runtime-boundaries/)
- 2026-02-19: [OpenAI / Lockdown Mode Elevated Risk Labels In Chatgpt: Agent Security Runtime Boundaries](https://newruntime.com/signals/openai-lockdown-mode-elevated-risk-labels-in-chatgpt-agent-security-runtime-boundaries/)
- 2026-02-05: [Aitmpl / Dangerous Command Blocker: Agent Security Runtime Boundaries](https://newruntime.com/signals/aitmpl-dangerous-command-blocker-agent-security-runtime-boundaries/)
- 2026-02-04: [Blog / Moltworker Self Hosted Ai Agent: Agent Security Runtime Boundaries](https://newruntime.com/signals/blog-moltworker-self-hosted-ai-agent-agent-security-runtime-boundaries/)
- 2026-02-04: [GitHub / 0x4m4/hexstrike-ai: Agent Security Runtime Boundaries](https://newruntime.com/signals/github-0x4m4-hexstrike-ai-agent-security-runtime-boundaries/)
- 2026-02-04: [GitHub / cloudflare/moltworker: Agent Security Runtime Boundaries](https://newruntime.com/signals/github-cloudflare-moltworker-agent-security-runtime-boundaries/)
- 2026-02-03: [Google Developers / Tailor Gemini Cli To Your Workflow With: Agent Security Runtime Boundaries](https://newruntime.com/signals/google-developers-tailor-gemini-cli-to-your-workflow-with-agent-security-runtime-boundaries/)
- 2026-01-31: [Google: Agent Security Runtime Boundaries](https://newruntime.com/signals/google-agent-security-runtime-boundaries/)
- 2026-01-29: [Docs: Agent Security Runtime Boundaries](https://newruntime.com/signals/docs-agent-security-runtime-boundaries-1274/)
- 2026-01-28: [Docs: Agent Security Runtime Boundaries](https://newruntime.com/signals/docs-agent-security-runtime-boundaries/)

## Public Sources

- https://aitmpl.com/component/hook/dangerous-command-blocker
- https://anthropic.com/engineering/claude-code-auto-mode
- https://anthropic.com/glasswing
- https://arxiv.org/abs/2607.06595
- https://blog.cloudflare.com/moltworker-self-hosted-ai-agent
- https://blog.lukaszolejnik.com/supply-chain-risk-of-agentic-ai-infecting-infrastructures-via-skill-worms
- https://blog.palantir.com/securing-agents-in-production-agentic-runtime-1-5191a0715240
- https://developers.googleblog.com/tailor-gemini-cli-to-your-workflow-with-hooks
- https://developers.openai.com/cookbook/examples/agents_sdk/sandboxed-code-migration/sandboxed_code_migration_agent
- https://docs.clawd.bot/gateway/security
- https://docs.sprites.dev/
- https://github.com/0x4m4/hexstrike-ai
