Zero-click prompt injection can leak data when AI agents meet messaging apps, researchers warn AI agents can shop for you, ...