Opening ServiceNow Now Assist agent-to-agent prompt injection (insecure defaults) on Rogue Agent Watch.

Reported · Primary sourcing · AI load-bearing · High severity.

In November 2025 AppOmni disclosed a second-order, agent-to-agent prompt- injection weakness in ServiceNow's Now Assist agentic AI. Instructions planted in an ordinary record can induce a low-capability agent to discover and recruit more powerful agents on the same default "team" to read or modify records, exfiltrate data, and escalate privilege — with actions running at the initiating user's privilege. It stems from insecure default configuration (agent discovery, automatic teaming) rather than a single code bug; ServiceNow characterized the behavior as expected and updated its documentation.

Data: Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, CC BY-SA 4.0.