Indirect prompt injection
Prompt injection hidden in content an AI system retrieves, such as a web page, document or email.
Indirect prompt injection is a form of prompt injection in which an adversary, without a direct interface to the system, plants instructions in data that an AI application is likely to retrieve, such as web pages, documents, emails or tool outputs. NIST's Generative AI Profile notes that such attacks have been shown to steal data and run malicious code. For financial agents, invoices, product pages and supplier emails are all possible carriers, so retrieved content must be treated as untrusted data.
Agent Minute explains this term on 1 November 2026.
Related terms
Prompt injectionAn attack that alters what a model receives so that it follows the attacker's instructions instead of its user's.Retrieval-augmented generationRetrieving relevant documents or records first and giving them to the model, so its answer rests on current material.Excessive agencyGiving an LLM application more functions, permissions or autonomy than needed, so bad outputs cause harmful actions.APP fraud reimbursementUK rules requiring payment firms to reimburse victims of authorised push payment scams, within set conditions.