---
term: "Indirect prompt injection"
category: "AI risks and safety"
url: https://agenticopenfinance.com/glossary/indirect-prompt-injection
source: AgenticOpenFinance glossary
---

# Indirect prompt injection

> Prompt injection hidden in content an AI system retrieves, such as a web page, document or email.

Indirect prompt injection is a form of prompt injection in which an adversary, without a direct interface to the system, plants instructions in data that an AI application is likely to retrieve, such as web pages, documents, emails or tool outputs. NIST's Generative AI Profile notes that such attacks have been shown to steal data and run malicious code. For financial agents, invoices, product pages and supplier emails are all possible carriers, so retrieved content must be treated as untrusted data.

Related terms: [Prompt injection](https://agenticopenfinance.com/glossary/prompt-injection.md), [Retrieval-augmented generation](https://agenticopenfinance.com/glossary/retrieval-augmented-generation.md), [Excessive agency](https://agenticopenfinance.com/glossary/excessive-agency.md), [APP fraud reimbursement](https://agenticopenfinance.com/glossary/app-fraud-reimbursement.md)
