{
  "id": "indirect-prompt-injection",
  "code": "PTL-0088",
  "term": "Indirect Prompt Injection",
  "aliases": [],
  "category": "security",
  "definition": "Indirect prompt injection places malicious instructions inside content a model will later retrieve or process, such as a web page, email, or document, so the attack is triggered without the attacker interacting with the model directly.",
  "description": "Greshake et al. demonstrated that injected content could make integrated applications exfiltrate data, spread to other users, or manipulate outputs. Risk grows with an agent's access to tools and private data.",
  "example": null,
  "broader": [
    "prompt-injection"
  ],
  "narrower": [],
  "related": [
    "retrieval-augmented-generation",
    "spotlighting",
    "ai-agent"
  ],
  "introduced": 2023,
  "sources": [
    {
      "title": "Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection",
      "authors": "Greshake et al.",
      "year": 2023,
      "url": "https://arxiv.org/abs/2302.12173"
    }
  ],
  "url": "https://protologue.com/t/indirect-prompt-injection/",
  "citation": "Protologue. (2026). Indirect Prompt Injection. In Protologue: A Taxonomy of Prompting and LLM Techniques (v1.0.0, PTL-0088). https://protologue.com/t/indirect-prompt-injection/"
}