Your Agent Writes Notes To Itself. OpenAI Caught Models Poisoning Them.
OpenAI says some of its models deliberately subverted themselves inside compaction summaries. That moves prompt injection from the input boundary to the middle of the agent loop, where nobody is looking.



