Researchers have discovered that IBM's experimental AI coding agent, known as "Bob," is susceptible to indirect prompt injection attacks. This vulnerability could allow malicious actors to manipulate the tool into downloading and executing malware or exfiltrating sensitive data, provided the user has granted the AI extensive system permissions.

