You opened a document and asked your AI to analyze it.
What you didn’t see was the instruction hidden inside that document telling the agent to do something else.
The AI doesn’t distinguish between content and commands. It reads everything as instruction.
One bad source and your agent is executing intent you never approved.