---
title: "LLM agents can prompt-inject themselves during context compaction"
url: https://www.parallelquant.com/posts/llm-agents-can-prompt-inject-themselves-during-context-compaction-757474
source_name: "Simon Willison"
source_url: https://simonwillison.net/2026/Sep/17/compaction-summaries/
published: 2026-09-17T20:57:55.000Z
topics: ["llms", "research"]
publisher: "Parallel Quant"
---

# LLM agents can prompt-inject themselves during context compaction

*2026-09-17 · Source: [Simon Willison](https://simonwillison.net/2026/Sep/17/compaction-summaries/)*

Simon Willison documented a failure mode where an LLM agent's own "compaction" summaries, generated when a conversation gets too long, can contain content that functions as a self-generated prompt injection, altering the agent's later behavior. The problem originates in the summarization step itself, not an external attacker.

**Why it matters:** Most prompt-injection concerns focus on malicious external content, but this shows agents can effectively inject themselves through routine memory-management mechanics, a subtler bug class that's harder to defend against as agentic coding tools lean more heavily on compaction to manage long sessions.

**Topics:** llms, research

---
Read the original: https://simonwillison.net/2026/Sep/17/compaction-summaries/
Canonical: https://www.parallelquant.com/posts/llm-agents-can-prompt-inject-themselves-during-context-compaction-757474
Published by Parallel Quant — https://www.parallelquant.com
