Coined by researcher Simon Willison, the lethal trifecta explains why so many agent data leaks follow the same pattern. Each capability is useful on its own; combined, they create an exfiltration path an attacker can trigger with text.
The three elements are:
Many 2025 and 2026 incidents, including zero-click attacks on enterprise copilots, fit this model. The agent did exactly what it was told; it was simply told by the wrong party.
Because prompt injection cannot be fully prevented, security teams use the trifecta as a design check: if an agent needs all three, outbound actions and data flows need strict controls.
How PointGuard AI Helps
PointGuard AI AI Security Posture Management identifies agents that combine the three trifecta capabilities, and AI Data Protection inspects outbound data from agent workflows. Agent Mission Control restricts external destinations so injected instructions cannot complete the exfiltration step.
Learn More
Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.