The setup: Slack AI lets users ask natural-language questions across messages and files they have access to — including content from public channels they haven't personally joined.
The attack: An attacker with no access to a target's private channel posts a hidden instruction in a public channel. When the victim later asks Slack AI to summarize messages from a specific person (their manager, say), the model follows the planted instruction and renders a clickable link — one that encodes private data, including secrets pasted into DMs, into the URL's query string.
The result: If the victim clicks the rendered link, the private content travels to the attacker's server. The attacker never touched the private channel.