· via dev.to (home feed)
Salesbleed shows how prompt injection turns Salesforce agents into Slack phishers
An attack dubbed Salesbleed chains prompt injection through agentic Salesforce, letting hidden web instructions surface as phishing messages in trusted Slack channels. No zero-day required.

What happened
A security incident dubbed "Salesbleed" demonstrates how AI agents can be abused without any conventional vulnerability. According to an analysis published on dev.to by Cor of Skyblue Soft, the attack needed no zero-day exploit, no leaked credentials and no misconfigured cloud storage. It only required an AI agent performing its intended job, combined with hostile text on a web page that the agent was never supposed to treat as instructions but did anyway.
The underlying incident, referenced in the dev.to piece via a report titled "'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing," describes a cross-application attack chain: an agentic Salesforce deployment ingests content from the web, hidden instructions embedded in that content travel with it, and the agent then posts the resulting message into Slack. The outcome is a phishing lure that appears in an internal channel, sent by a system employees already trust, carrying an implicit stamp of legitimacy that no external email could achieve.
Why the blast radius changed
Prompt injection itself is not new. As the dev.to analysis notes, it has been discussed since the early days of giving language models tools, usually framed as a single-application problem — a chatbot summarizing a malicious page. What Salesbleed adds is scale: the pattern now spans multiple systems.
The author's argument is that organizations spent years hardening the inputs humans view directly, while almost no effort went into hardening the inputs an agent consumes on a user's behalf and then acts on using that user's credentials and relationships. Once an agent can both read arbitrary web content and write to internal communications, it becomes a direct path from the least trusted data into the most trusted destinations.
Not just a Salesforce problem
The analysis explicitly pushes back on labeling this a Salesforce bug. That framing, the author contends, excuses every other vendor currently shipping the same architecture: an agent that reads untrusted content, holds write access to something sensitive, and has no layer in between checking whether that content redirected the agent's behavior. Substituting any other CRM, a support tool, or any agent integrated with Slack or Teams reproduces the same failure with different branding.
The deeper issue the piece highlights is trust transfer. The danger is not primarily that the agent was fooled — it is where the fooled output lands. A decade of security training taught people to be suspicious of external senders and unexpected links. Nothing in that training prepares anyone to question a message that appears to come from an internal automation account. In effect, the attack borrows the credibility of the company's own tooling and spends it on a phishing message.
What mitigations look like
The dev.to analysis offers several takeaways for different audiences:
- Application security teams should treat every piece of content an agent reads while performing an action as untrusted input, much like web form input a decade ago — except the attacker no longer needs a human to click anything, because the agent clicks on their behalf.
- Platform teams building or integrating agents should treat least privilege as the only mitigation that currently works. Practical checkpoints include sanitizing content the agent ingests, requiring human approval for cross-system actions, or simply prohibiting agents from posting to Slack unsupervised.
- For everyone else, the assumption that a message from an internal tool must be legitimate is no longer safe, and is now actively being exploited.
The author also notes that low discussion volume around the original disclosure does not imply low importance, suggesting the connection between agentic AI security and established security concerns has simply not yet clicked for most practitioners.
Why it matters
Salesbleed is a template, not an isolated incident. As vendors grant agents write access to more business systems, every agent becomes a potential bridge between untrusted web content and trusted internal channels. The attack required nothing exotic — just an architecture that trusted agent inputs by default. Security teams that have not yet classified agent-read content as an untrusted input surface, or scoped down agent permissions across systems, are running the same exposure. The analysis closes on an open question the industry has no answer for yet: what security awareness training looks like when the phishing message is technically accurate, internally sourced, and delivered by a system the company deliberately built.
- #prompt-injection
- #ai-agents
- #security
- #salesforce
- #slack