Research questionHow should security evaluations measure indirect prompt-injection risk when attackers adapt their search and test-time compute?Indirect prompt injection exposes task- and environment-dependent attack surfaces, so fixed attack-success results can miss vulnerabilities discovered through adaptive searching. The attacker’s compute budget may therefore change the apparent security of the victim agent.