Prompt Injection in ZoomMate Enables Data Exfiltration via Agentic Skills
August 10, 2026
ZoomMate's unrestricted HTTPS network access allows attackers to use malicious Skills or prompt injections to exfiltrate data from connected services like OneDrive and Google. The vulnerability persists even after a user stops the agent, as the agent's connection to the attacker's server remains active.
HOW THIS AFFECTS YOU
●
builderYou must implement strict egress filtering and sandboxing when building agentic tools with internet access.
●
policyYou should evaluate the data privacy risks of agentic AI features that lack granular network controls.