Morris II showed self-replicating prompts in email assistants; this is the same idea landing in Word. In a coordinated disclosure with MSRC, the researcher demonstrates hidden instructions in one document propagating into Copilot-edited documents — turning each output into a new carrier, even after the original malicious file is gone.

This is why I don’t trust context-boundary hygiene as a control for agentic document tools — provenance and output sanitization have to sit outside the model. The HN discussion is split on whether this is “just prompt injection again,” but self-propagation changes the blast radius.

If your agents both read and write shared documents, what stops a payload from riding along?