Prompt injection / manipulation
A malicious or malformed input instructed the agent to spend or exfiltrate credentials. The fix is a merchant allowlist and a human-in-the-loop flag for unknown vendors.
How to stop it
Configure merchant allowlist + FLAG for unknown in sipi.bot. Every transaction matching this pattern is then BLOCKed or FLAGged before any money moves.
Merchant allowlist
Prompt-injected purchases at unknown or malicious merchants.
allow: [openai.com, stripe.com]Category rule
A GPU splurge draining the budget meant for SaaS tools.
category: compute, daily_max_usd: 501 documented prompt injection incident
| Incident | Loss | Provider | Year | Source |
|---|---|---|---|---|
| Fake bug report tricked an agent into leaking a live AWS key | Cost not disclosed | AWS | 2025 | Medium (Predict) ↗ |
Close this gap in your agents
One rule covers every incident on this page. Set it once in sipi.bot and every matching transaction is evaluated in <5ms, before the money moves.