Image-based attacks against multimodal LLMs — visible-text injection (P1) and OCR poisoning (P5), anchored in the NexaCore DocReceive intake scenario.