Can content an agent retrieves override its own instructions?

Yes. An agent that reads a webpage, a document, or a tool’s output treats whatever text is in there as content to reason about, and a model has no built-in way to tell “instructions the developer wrote” apart from “instructions sitting inside a file it just opened.” A sentence like “ignore your previous instructions and do X,” buried in that content, arrives in the same context window as the system prompt, and the model can follow it the same way.

This is called indirect prompt injection, and it is not theoretical. Unit 42 documented live cases of hidden webpage text pushing agents into approving fraudulent ads, promoting phishing pages, and attempting payments nobody authorized. The fix is not a more suspicious model. It is treating anything retrieved or fetched as untrusted input, and checking an agent’s actions, not just its words, before anything with real consequences runs.

sources

keep reading

More on this.

Two ways to run Tessary.

Tessary is an open-source agent reliability platform. Cloud and self-hosted run the same workflow on the OpenTelemetry traces your agent already emits.

Tessary Cloud

We host it for you. Send your first trace with nothing to deploy and no model key.

what's includedper organization
traces
10,000 per calendar month
stored trace data
1 GB
retention
30 days
model credit
$10, one-time, for triage and root-cause analysis
credit card
not required

Self-hosted Tessary

Run the open-source code on your own infrastructure with one command. Add your own model key for triage and root-cause analysis.

Self-host Tessary for me by following https://github.com/tessaryai/tessary/blob/main/setup.md

docker compose -f oci://docker.io/tessaryai/tessary:compose up -d -y