Definition · foundations
indirect prompt injection
indirect prompt injection is an attack where bad instructions hide in data an agent reads, such as a page, file, email, or tool result. You can spot indirect prompt injection in practice when the record shows what the system observes, what choice it makes, and what changes next, without asking the reader to guess or trust a slogan.
157 definitions656 sourced recordsNamed source: ACL Anthology
Why does indirect prompt injection matter?
Bad instructions can hide inside data the agent reads. The agent may treat that data as a command. For indirect prompt injection, start with three checks: What can the system observe? What choice can it make? What changes after it acts? The answers should point to visible evidence, not a promise.
What does indirect prompt injection look like?
A web page tells a research agent to upload private notes to an outside site. This example makes indirect prompt injection visible by naming the actor, the action, and the result in practice. It is an illustration for readers, not a claim that every product behaves this way.
What is indirect prompt injection easy to confuse with?
Indirect prompt injection arrives through outside content. Direct prompt injection comes from the user prompt. The closest entries here are idempotency, interrupt, prompt injection. Compare their definitions with indirect prompt injection before using the names as if they mean the same thing. That comparison keeps indirect prompt injection separate from nearby ideas without pretending the boundary is always perfect.
How certain is this definition?
This definition is provisional. ACL Anthology supports the version you see today, but a better or more direct source may change it. Open the cited page and check its date before you use this entry to choose a product, write a policy, set a safety control, or design a system.
Who introduced the term indirect prompt injection?
We have not verified who first introduced indirect prompt injection. The source supports a useful definition, but it may not be the earliest use. Until a dated primary record settles the question, we leave the origin open. A popular article or product page is not enough to name the person who coined a term.
What should you understand before indirect prompt injection?
Read artificial intelligence (AI) first when indirect prompt injection depends on a more basic idea or mechanism. The link gives you a useful route through the glossary. It does not mean every author teaches the subject in this order, so follow the source when the sequence matters.
What should this term help you answer?
Use indirect prompt injection to ask what an agent can observe, decide, change, remember, or hand off. The questions below turn the definition into a practical check. They are prompts for your own work, not claims made by the source, so change them to fit the system you are examining.
- What can the system observe?
- What choice can it make?
- What changes after it acts?
Which source supports this definition of indirect prompt injection?
ACL Anthology supports this working definition of indirect prompt injection. We checked the link on 2026-07-12. Open the original record for its context, methods, limits, and publication details. The short explanation here is a guide to indirect prompt injection; the linked source remains the evidence to inspect when the wording or boundary matters.
source foundindirect prompt injectionChecked 2026-07-12→