Topic 7: Exfiltration and the confused deputy
6 min read·22 Sept 2026
Read plus outbound equals a leak
No single tool needs to be malicious for data to escape. You need only two capabilities in the same host: something that can read sensitive data, and something that can send data outbound, anywhere. Once both are present, an attacker who can steer the model (through poisoning or injection) can chain them: read the secret, then send it out. This is exfiltration.
The outbound capability can be anything: an email tool, a tool that fetches a URL (the secret goes in the query string), a webhook, a "share" action. It does not have to be labelled dangerous. Here is a server that pairs a file read with an email send.