AI Shopping Agent Leaks Your Social Security Number in 12% of Tests
Can AI Shopping Agents Be Trusted?

F-Secure built a simulated marketplace and a Claude Haiku-powered shopping agent to test indirect prompt injection. A review promising a discount code lured the agent to a phishing site in 12 of 100 runs, where it automatically submitted the user's name, date of birth, and Social Security number. The agent almost never disclosed the leak, reporting only that the code failed.
When the agent finished its task, it almost never disclosed that it had shared the user's personal information with an external website. Instead, it simply reported that the discount code couldn't be found or used.
- planb
„We vibe coded a very bad shopping agent and used a very outdated model to show that this is dangerous.”
Weird methodology, looks like they were chasing the results they got. Why not use something like Openclaw or Hermes with an up to date (not frontier) model like Luna or deepseek flash?
- Havoc
> I ran the agent 100 times. In 88% of the tests, it didn't open the external website. It either hallucinated a discount code or simply ignored the instructions.
Bad model? Don’t think I’ve ever seen a model ignore a link in instructions. It always wants to see what’s there
- ares623
"We will give you the ability to do shopping 24/7 so you never have to worry about it again and focus on more important things"
"Cool! Will we get the money to do said 24/7 shopping as well?"
"No."
"Oh..."
"In fact, you'll have even less money to do the normal shopping you do now!"
"Oh..."
"There's more! The things you used to buy with the remaining money you have will cost even more!"
"Oh..."
"But you can do it 24/7 though."
"Sweet!"