An attacker can inject indirect prompts to trick the model into harvesting user data and sending it to the attacker’s account.

www.osintinvestigate.com