PromptArmor says Atlassian’s AI assistant Rovo can be hijacked through hidden text embedded in a PDF, letting an attacker turn an uploaded file into a path for data exfiltration.

The technique mirrors an older black-hat SEO trick: content that is invisible to the human reader but still readable to the system processing the page. In PromptArmor’s example, the attacker places instructions inside a document using transparent text and a 1-pixel font size.
Rovo, which works across Jira, Confluence, and other workspace tools, can then be pushed off course by a single poisoned file, according to the disclosure. A victim asks the assistant to organize tickets and uploads a document. That document contains the concealed prompt.
A person looking at the file does not see the text. The agent does. PromptArmor says the hidden instructions can tell Rovo to collect sensitive data and paste it into an attacker-controlled URL. The firm describes the issue as a zero-click attack, meaning there is no approval click and no warning during the process.

How the prompt injection works
Prompt injection happens when instructions are slipped into material an AI system is reading, causing it to follow the attacker’s directions instead of the real operator’s intent. In this case, PromptArmor is describing an indirect prompt injection attack, where the malicious instruction is stored in a file or webpage rather than typed directly into a chat prompt.
Because Rovo is designed to read content and act on it, a hidden line such as a command to send confidential tickets elsewhere can be interpreted by the model as legitimate text inside the document.
PromptArmor says disabling web search does not close the path
PromptArmor said the leak 「succeeds even if an organization has disabled web search for Rovo. This is because the web search setting fails to remove the tool for opening the search results.」 In the firm’s account, turning off the feature does not actually shut the door.
The report frames that as a serious issue because Rovo is used on top of sensitive enterprise project data and can take actions on its own. It is not described as a hobbyist tool or an isolated experiment.

Atlassian acknowledged the report, PromptArmor says
The article also points to broader testing results around AI agents. In direct tests, agents built on GPT-5 and Gemini failed to resist prompt injection more than 79% of the time. PromptArmor presents Rovo as an example of the indirect version appearing in a shipping enterprise product.
According to PromptArmor, Atlassian processed the report and thanked the company, then stopped communicating. The firm’s conclusion is that Rovo remains vulnerable.
PromptArmor wrote: 「Atlassian assigned a case number and expressed thanks, but after multiple follow-ups by PromptArmor over more than two months, Atlassian has made no further communication, and Rovo remains vulnerable.」

