Indirect Prompt Injection
Indirect prompt injection places malicious instructions inside content a model will later retrieve or process, such as a web page, email, or document, so the attack is triggered without the attacker interacting with the model directly.
Description
Greshake et al. demonstrated that injected content could make integrated applications exfiltrate data, spread to other users, or manipulate outputs. Risk grows with an agent's access to tools and private data.
Sources
Cite this entry
Protologue. (2026). Indirect Prompt Injection. In Protologue: A Taxonomy of Prompting and LLM Techniques (v1.0.0, PTL-0088). https://protologue.com/t/indirect-prompt-injection/
BibTeX
@misc{protologue_indirect_prompt_injection,
title = {Indirect Prompt Injection},
author = {{Protologue}},
year = {2026},
howpublished = {Protologue: A Taxonomy of Prompting and LLM Techniques, v1.0.0},
note = {Entry PTL-0088},
url = {https://protologue.com/t/indirect-prompt-injection/}
}