Generalization to Agents That Share Their Thought Process
Determine whether the findings on covert indirect prompt-injection success and the ICoA attack in ReAct-style tool-using agents apply to agents that share their thought process with the user.
References
Second, our tests focus only on ReAct-style loops. We do not know if the results apply to agents that share their thought process with the user.
— Will the User Ever Know? Covert Indirect Prompt Injection on Tool-Using LLM Agents
(2608.30362 - Lee et al., 31 Aug 2026) in Limitations section