Two failures, one sentence

Scene one. You ask an AI agent to summarize your inbox. One email contains text written for the agent, not for you. The agent reads it, treats it as something to act on, and acts. No server crashed, no memory was corrupted, no traditional exploit ran. The model read text ...