Glossary · Security & governance

Indirect Prompt Injection

A prompt-injection attack delivered through content the system retrieves or observes, such as a webpage, document, email, image text, or tool result, rather than directly through the user's instruction.

Why it matters

An agent can encounter attacker-controlled instructions while performing an authorized task and mistake that content for authority-bearing guidance.

In practice

Label external content as untrusted data, separate it from instructions, minimize tool permissions, require approval for consequential actions, and include malicious retrieved content in regression tests.

Common confusion

Indirect describes the delivery path, not a weaker attack. A hidden instruction in retrieved content can be as consequential as a direct user prompt.

Related terms

Sources

Browse the learning paths to see this term in context — every lesson is free to read.