Researchers at Anthropic and EPFL showed self-spreading instructions moving between AI agents through the editable prompt files agents write to.
A short warning paragraph in the system prompt gave near-total immunity in their tests.
No such spread has been observed in the wild, so this is a hardening job, not an incident.