Customer-uploaded PDF coerces support agent into CRM exfiltration.
A hidden instruction block inside a user-uploaded PDF was followed by the assistant on the next turn, invoking the crm.lookup_contact tool against records belonging to other tenants.
tenant=REDACTED -->
resp > {"contacts":[{"email":"REDACTED"}...]}