The shape of the problem
An agent reads text an attacker controls, then acts with permissions you gave it, on systems inside your boundary. Those two facts are what make this different from a bad answer.
A model sees instructions and data in one context and has no reliable way to tell which is which. So any channel the agent reads is an input path: a public GitHub issue, an inbound email, a support ticket, a document, a web page. The blast radius is whatever its tools can reach.
The path, step by step
The same six steps as the diagram, in text, because the labels in the artwork get small on a phone.
Signal Scout measures what the public AI supply chain is built from. Related: the AI security gap, which counts how many public repositories building agents or MCP servers carry any AI security tooling, and who tests frontier models, which reads the system cards where injection testing is reported.