Prompt injection to RCE in AI agentsWe bypassed human approval protections for system command execution in AI agents, achieving RCE in three agent platforms.