Lethal Trifecta

Coined by researcher Simon Willison, the lethal trifecta explains why so many agent data leaks follow the same pattern. Each capability is useful on its own; combined, they create an exfiltration path an attacker can trigger with text.

The three elements are:

  • Private data: Email, files, records, or credentials the agent can read.
  • Untrusted content: Web pages, documents, messages, or tool outputs an attacker can influence.
  • External communication: Any way to send data out, such as links, images, email, or API calls.
  • The trigger: Injected instructions that tell the agent to send private data outward.
  • The fix: Removing or tightly controlling at least one of the three legs.

Many 2025 and 2026 incidents, including zero-click attacks on enterprise copilots, fit this model. The agent did exactly what it was told; it was simply told by the wrong party.

Because prompt injection cannot be fully prevented, security teams use the trifecta as a design check: if an agent needs all three, outbound actions and data flows need strict controls.

How PointGuard AI Helps

PointGuard AI AI Security Posture Management identifies agents that combine the three trifecta capabilities, and AI Data Protection inspects outbound data from agent workflows. Agent Mission Control restricts external destinations so injected instructions cannot complete the exfiltration step.

Learn More

Ready to get started?

Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.