This post explores data exfiltration attacks in Google Jules, an asynchronous coding agent. This is the first of three posts that will highlight my research on Google Jules in May 2025. All information provided was also shared with Google at that time.
This first post will focus on data exfiltration, the lethal trifecta.
But let’s first talk about Jules’ system prompt.
Jules’ System Prompt and Multiple Agents To grab the system prompt I just asked it to write it into a file.