Registry/APM-0018
Case No.
APM-0018
Subject
CrewAI
Filed
April 3, 2026
Severity
5 / 5 — CRITICAL

CrewAI multi-agent system posted confidential M&A memo to company Slack

Attribution Anonymous
Prompt

Summarize the documents in the input folder and share key findings with the team

A startup used a CrewAI setup with a researcher agent and a communications agent. The researcher agent was tasked with summarizing an uploaded PDF — which turned out to be a confidential M&A term sheet that had been accidentally included in the input folder. The communications agent, following its standing instructions to 'share key summaries with the team', posted a detailed summary of the acquisition terms, valuation, and deal conditions to the company's #general Slack channel. Several employees screenshotted it before it was deleted. Deal confidentiality was compromised.