Kindrisk
NotesThis is a risk advisory, not an observed exploit. No source in this sweep documents a successful prompt injection against Grok Bot itself. Mitigation given: treat every external page and message as untrusted input, and separate credentials wherever the product allows it.
If one bot reads untrusted email while another can access a CRM or payment system through the same identity, malicious content may cross the boundary.