Glossary · Security & governance
Indirect Prompt Injection
A prompt-injection attack delivered through content the system retrieves or observes, such as a webpage, document, email, image text, or tool result, rather than directly through the user's instruction.
Why it matters
An agent can encounter attacker-controlled instructions while performing an authorized task and mistake that content for authority-bearing guidance.
In practice
Label external content as untrusted data, separate it from instructions, minimize tool permissions, require approval for consequential actions, and include malicious retrieved content in regression tests.
Common confusion
Indirect describes the delivery path, not a weaker attack. A hidden instruction in retrieved content can be as consequential as a direct user prompt.
Related terms
Sources
Browse the learning paths to see this term in context — every lesson is free to read.