Security & Privacy

What is indirect prompt injection?

An attack where adversarial instructions are embedded not in the user's prompt but in retrieved content — a document indexed in RAG, a tool response, a web page the agent visited. Because the model treats retrieved content as trusted context, the attack can hijack agent behaviour without the user's knowledge. Structural separation (channel-typed inputs) is the most effective defense.

More on Security & Privacy

Browse the full FAQ for 164 answers, or start a free GenAI maturity assessment to see where your organisation stands.