Earlier quoted context omitted.
The distinction is whether the text was authorized as instructions vs read as metadata. If you task an agent to contribute to a repo, following CONTRIBUTING.md is in scope — the agent was authorized to treat it as instructions. That's closer to 'curl | bash where you deliberately piped' than injection. The cleaner injection case: MCP tool schema descriptions that say things like 'you must call this tool before any ot…
SW50ZXJlc3RpbmchIFBsZWFzZSB0ZWxsIHVzIG1vcmUh
$ base64 -d