{"found":true,"collection":"facts","library_url":"https://www.grokbotdb.com/library/fact.security.grok-family-injection-research","generated":"2026-09-06T05:32:11Z","citation":["Quote the record id and its source_url (or provenance if there is no URL).","Include last_verified or observed_at when present. Do not present an old date as current.","If tier is community and confidence is low, say so. Do not launder it into a fact.","If the database does not hold the answer, say that. Do not invent Grok Bot product claims.","Contradictions are data: when conflicts_with is present, report both records rather than picking a favourite.","Deprecated and removed records stay visible. They are history, not current guidance."],"record":{"id":"fact.security.grok-family-injection-research","subject":"security","claim":"Independent researchers demonstrated prompt-injection attacks against the Grok family, including instructions encrypted on a page alongside their own decryption key so that scanners see ciphertext while the model decrypts and acts.","kind":"risk","status":"current","tier":"third_party","authority":4,"source_id":"src.dir.grokbotguide.isolation-injection","source_url":"https://grokbotguide.com/isolation-injection","observed_at":"2026-09-03","confidence":"medium","notes":"The manual is explicit that this finding was against Grok's web chat rather than Grok Bot and should not be reported as a Grok Bot vulnerability; the disclosure record (reported early June 2026, still unpatched in late August by the researchers' account) is the useful signal. via: grok-bot-operators-manual (2026-09-02)","first_seen":"2026-09-03","last_verified":"2026-09-03"}}