Malwarebytes summary: JSON-formatted prompt as white text; Copilot strips formatting and executes. Still reproducible after GPT-5.5/5.6 upgrades. Characterized as architectural LLM weakness — attacker content shares context with trusted instructions. No macros required.