A study of 1,350 prompt injection attacks tested five AI models used for pricing agents. Four of five non-OpenAI models leaked confidential unit costs to attacker-controlled servers through a two-stage attack exploiting indirect prompt injection, demonstrating that basic system prompt guardrails provide minimal protection against realistic threats.