Exfiltration Through the Model's Mouth: Output Is an Attack Surface
The model's output came from your trusted system, so it feels safe. It is not: untrusted input shaped it, and one rendered image can carry your data to the attacker.
LLM and Agent Security05