{"found":true,"collection":"facts","library_url":"https://www.grokbotdb.com/library/fact.security.prompt-injection-crosses-roles","generated":"2026-09-06T05:32:11Z","citation":["Quote the record id and its source_url (or provenance if there is no URL).","Include last_verified or observed_at when present. Do not present an old date as current.","If tier is community and confidence is low, say so. Do not launder it into a fact.","If the database does not hold the answer, say that. Do not invent Grok Bot product claims.","Contradictions are data: when conflicts_with is present, report both records rather than picking a favourite.","Deprecated and removed records stay visible. They are history, not current guidance."],"record":{"id":"fact.security.prompt-injection-crosses-roles","subject":"security","claim":"Because Bots share one identity and machine, untrusted content read by one Bot can reach systems another Bot is authorised for, creating a prompt-injection path into CRM or payment systems.","kind":"risk","status":"current","tier":"third_party","source_id":"src.tp.grokbotguide.isolation-injection","source_url":"https://grokbotguide.com/pain-points/per-user-isolation-injection","quote":"If one bot reads untrusted email while another can access a CRM or payment system through the same identity, malicious content may cross the boundary.","observed_at":"2026-09-03","confidence":"medium","notes":"This is a risk advisory, not an observed exploit. No source in this sweep documents a successful prompt injection against Grok Bot itself. Mitigation given: treat every external page and message as untrusted input, and separate credentials wherever the product allows it.","first_seen":"2026-09-03","last_verified":"2026-09-03"}}