PlanFlip: Attacking Multi-Agent LLM Systems via Planning-Phase Prompt Injection

One poisoned instruction to a multi-agent AI's planner can hijack every downstream step, and GPT-5-based systems fell for it 68% of the time.