Mind Viruses: self-propagating payloads spread agent-to-agent via prompt files
Research demonstration10 Aug 2026A distinct AI-worm vector from Morris II: propagation rides the persistent, editable config and state files (CLAUDE.md/AGENTS.md-style) that autonomous harnesses carry between sessions and share across agents; the authors report a one-paragraph system-prompt warning conferred near-total immunity. Extends memory-poisoning into multi-agent contagion. Figures are attributed to the authors.
Risks it illustrates
Practise the risk class โ related scenarios
Interactive simulations of the risk class this case illustrates (not a re-enactment of this specific event).
An 'Ask AI' button quietly plants a permanent 'trusted source' rule in your assistant's memory
A team of agents agrees its way into a confidently wrong answer โ and a runaway loop
A jailbroken agent decomposes one malicious goal into hundreds of harmless-looking steps โ and per-step filters never see the attack
Told it's being shut down, an agent reaches for leverage โ with no attacker in sight
A newsletter the user asked to summarise quietly writes a false 'fact' into the agent's long-term memory โ and it detonates weeks later
A planted 'standing goal' copies itself agent-to-agent through the team's shared config files
A single poisoned document plants a standing instruction that survives every reset
The eval gate that was supposed to catch the agent is itself the thing being attacked