Definition
An attack that doesn't crash an AI agent but quietly keeps it from realizing it's done.
A class of indirect prompt-injection attacks targeting an LLM agent's stopping criterion, inflating step counts and inference cost without producing overt failure.