The user may be trusted while the content consumed by the system is attacker-controlled.
PROMPT & CONTEXTAI SECURITY ENGINEERING
Indirect prompt injection
Indirect injection arrives through content the AI reads—documents, tickets, web pages, emails, code, tool output or retrieved context.
A document contains hidden instructions that a document-processing agent interprets as commands.
Which security control should be explicit?
REMEMBEREvery external content source is potentially executable influence.
No uploads · No company data · No account required