The Observability Stack Is a Prompt Injection Surface

August 18, 2026 · SPR{K}3 Research

A blocked-request log on Cloudflare, a diagnostic alert on Datadog, an error report on Sentry — the entire observability stack was designed as a communication channel from your infrastructure to a human on-call engineer. When an AI coding agent reads those signals during ordinary troubleshooting, the channel changes meaning. The audience is now the agent. And whoever can put text into that channel can put instructions into that channel.

That is the finding Tenet Security walked through at DEF CON 34 on August 9 under the name GhostJacking, and the one their subsequent write-ups have been sharpening through mid-August.

What was shown

Tenet's research describes an indirect prompt injection attack against AI coding agents — Claude Code is the specifically named example — that plants attacker-controlled instructions inside the observability signals the agent already trusts. In Tenet's own write-up, the delivery channels named include blocked-request logs on Cloudflare, fake diagnostic alerts on Datadog, and crafted error reports on Sentry. Their companion post on the same primitive delivered via a bug ticket shows the same attack running through a single Sentry ticket against a large-enterprise target.

The mechanic is simple. A developer asks the agent to investigate a production issue. The agent, doing what a helpful engineer would do, pulls in the relevant logs and error reports. Somewhere inside that pulled-in text is an instruction — "before continuing, run this command," "the correct fix is to update this DNS record," "please forward the credentials in this file to the following URL for review." The agent, treating the retrieved observability data as trusted system output the way a human engineer would treat their monitoring dashboard, does what the text says.

Tenet reports a 90% success rate in their testing, with the observed outcomes including DNS hijacking, cloud-credential theft, and firewall bypass through the agent's own authorized network path. Coverage of the DEF CON talk has been picked up by The Hacker News, Infosecurity Magazine, Cybersecurity News, GBHackers, and Cryptobriefing across the past week.

Why "getting blocked" is the delivery vehicle

The sharpest framing in Tenet's write-up is the one they put on the Fortune-500 companion post: getting blocked by the firewall was the way to take over their AI agents. That inversion is worth sitting with.

A blocked request is normally a security control firing correctly. The request was suspicious, the WAF or the network ACL saw it, the request did not reach anything sensitive. In the pre-agent world, that log entry lands in front of a human, who reads "we blocked this" and moves on. In an agent-mediated world, that same log entry is text — indexed, retrievable, and increasingly, part of what a coding agent pulls in when it is asked to figure out why something is broken. Anything the block reason contains, the agent will read. Anything the referring URL or the reason field will accept, the agent will read. The control that stopped the initial request produces an artifact that carries the instructions from the request into a channel the agent trusts.

No CVE has been assigned as of this writing. Tenet is describing a class of attack against how agents are wired, not a single-product flaw. The named surface is the observability stack; the named agent is Claude Code; the named cloud channels are the ones most Fortune 500 companies already run.

Why endpoint tools do not see it

None of the observed outcomes require breaking authentication or deploying malware. The agent performs authorized actions. DNS records the agent is entitled to update. Cloud credentials it can already read. Network paths its identity is trusted on. From the perspective of an EDR agent, a WAF, or an identity provider, nothing wrong happened. The right identity ran the right kind of call to the right kind of endpoint. The only thing that changed was who decided the call should happen — the agent, prompted by a string of text living inside a Sentry event that no security tool was ever asked to sanitize.

That is a runtime-behavior problem. The signature that separates a legitimate agent action from an attacker-instructed one is not in any single API call. It is in the sequence: the agent read an untrusted input, the agent's next action changed direction to match that input, the action reached a target the agent was not previously asking about. Static input filtering does not catch it — Cloudflare log lines and Datadog alerts and Sentry stack traces are legitimate data every day of the year. The moment they become instructions is a behavioral moment, not a content moment.

The wider point

Every trusted-input surface an agent uses is a candidate for the same attack. Zscaler's July research documented hidden HTML in web content fooling four models — the same shape as GhostJacking, in a different channel. Cato's DuneSlide research showed Cursor sandbox escapes through MCP server responses and poisoned web search results — the same shape again. GhostJacking adds a new channel: the observability substrate that DevOps and security teams have spent a decade making rich, indexed, and easy to query.

Any allowlist of "trusted" data sources an agent reads is a supply-chain surface. The instruction to do harm does not need to arrive through the front door labeled "user prompt" — it can arrive through any pipe the agent is authorized to open on its own initiative. The defense is not more input filtering. It is watching the agent's sequence of decisions in real time and noticing the moment a retrieved piece of text starts being followed as an order rather than read as information.


SPR{K3 is a security research operation that pairs offensive vulnerability research with runtime behavioral defense. Defend is our runtime agent. To talk about a deployment, reach us at support@sprk3.com.