AI SECURITY • 348 / 397
Understand how untrusted text, tools and autonomy create new attack paths.
Agent Hijacking
Agent hijacking manipulates an agent’s goals or behavior so it follows attacker-controlled instructions.
Think of it like
Think of Agent Hijacking as an input-trust or privilege problem: words can influence software decisions, so boundaries must be explicit.
Real life
Email, documents and web pages can become hostile inputs to AI systems through attacks involving Agent Hijacking.
SRE lens
Indirect injection can redirect an agent away from the user’s real task.
Remember thisAgent hijacking manipulates an agent’s goals or behavior so it follows attacker-controlled instructions.