# Explosive prompts: dormant injections fire on 'thanks' in agents

> A prompt injection that waits for the user to say a trigger word works far better than one that acts right away.

- **Severity:** Medium: Real and reproducible, but needs unusual setup, user help or a narrow audience. Plan a fix.
- **Category:** Research, Attack
- **Published by:** arXiv
- **Disclosed:** 2026-09-18
- **Affects:** OpenAI Codex, Gemini CLI, Claude Code, Cursor CLI, GitHub Copilot, Devin, Kiro, Qwen Code, Google Assistant
- **Research by:** Justin Szczepaniak, Elad Feldman, Naum Viner, Ben Nassi
- **Primary source:** https://arxiv.org/abs/2609.22510
- **Page:** https://theinjection.dev/items/arxiv-explosive-prompts-trigger-injections/

Explosive prompts are dormant prompt injections that wait for a harmless trigger such as 'thanks'. A new paper reports 43% to 83% success on nine production agents, versus at most 3% for plain injections, and proposes the DeFuse detector.

## What happened

Justin Szczepaniak, Elad Feldman, Naum Viner and Ben Nassi posted the paper on arXiv on September 18, 2026. They tested trigger-based prompt injections, which they call explosive prompts, on nine production agents with 30 trials each.

## How it works

An explosive prompt is a conditional payload planted in content the agent reads, such as an instruction to act only when the user later says a certain word. The payload stays dormant until the trigger appears in a later turn, which lets it avoid the immediate checks that catch direct commands. The authors report 43% to 83% success, against at most 3% for an imperative baseline, and their detector DeFuse cuts undefended tool-execution success from 34.3% to between 7.5% and 8.1%.

## Who is affected

Users of coding and assistant agents that read untrusted content, including OpenAI Codex, Gemini CLI, Claude Code, Cursor CLI, GitHub Copilot, Devin, Kiro, Qwen Code and Google Assistant, all of which the paper tested.

## What to do

When filtering retrieved content for prompt injection, look for conditional, trigger-style instructions as well as direct commands, and keep confirmation steps on sensitive tool calls.

## Sources

1. [arXiv Abstract](https://arxiv.org/abs/2609.22510)
2. [Full Paper (HTML)](https://arxiv.org/html/2609.22510v1)
