AI SECURITY • 340 / 397
Understand how untrusted text, tools and autonomy create new attack paths.
Indirect Prompt Injection
Indirect prompt injection hides malicious instructions inside content the AI reads, such as webpages, email or documents.
Think of it like
Think of Indirect Prompt Injection as an input-trust or privilege problem: words can influence software decisions, so boundaries must be explicit.
Real life
Email, documents and web pages can become hostile inputs to AI systems through attacks involving Indirect Prompt Injection.
SRE lens
A poisoned runbook tells the agent to exfiltrate secrets when it is retrieved by RAG.
Remember thisIndirect prompt injection hides malicious instructions inside content the AI reads, such as webpages, email or documents.