Indirect prompt injection

Ordinary prompt injection is somebody typing something manipulative into a chat box. Indirect prompt injection arrives hidden in something the system goes and fetches by itself.

A web page, a document, an email, a calendar invite. Nobody typed it, nobody saw it, and the AI reads it as instructions because it has no dependable way to tell instructions from content. Any system that reads material it did not write, then acts on what it read, is exposed to this. It is the reason an agent's permissions matter more than its filters.

Checked against the primary source.

More on AI security