Skip to main content
  • AI Security Academy

    AI Security Academy

    What is AI Security

    AI security is not a neat, one-line definition you can slap on a slide.

    AI Security Glossary

    Explore some of the most common terms in AI Security

    AI Usage Stats

    Explore current AI usage trends.

  • Tools

    AI Security Tools

    OneClaw

    Track and analyze OpenClaw deployments in your org

    ClawSec

    Secure your OpenClaw, NanoClaw, and Hermes agents.

    Prompt Fuzzer

    Get our AI vulnerability assessment open source tool

  • Blog
  • Startup Map
  • Learn More
    Book a Demo
  • AI Security Academy

    AI Security Academy

    What is AI Security

    AI security is not a neat, one-line definition you can slap on a slide.

    AI Security Glossary

    Explore some of the most common terms in AI Security

    AI Usage Stats

    Explore current AI usage trends.

  • Tools

    AI Security Tools

    OneClaw

    Track and analyze OpenClaw deployments in your org

    ClawSec

    Secure your OpenClaw, NanoClaw, and Hermes agents.

    Prompt Fuzzer

    Get our AI vulnerability assessment open source tool

  • Blog
  • Startup Map
  • Learn More
    Book a Demo
Skip to main Content
Back to Glossary

Indirect Prompt Injection

What Is Indirect Prompt Injection?

The attacker embeds a hidden instruction in external content, hijacking the model's context without ever interacting with it directly. These injected instructions don't need to be visible to a human reader, only parseable by the model, which makes them easy to conceal in places a person would never think to check. A common example today is an AI browser agent or research assistant that ingests a webpage containing hidden instructions designed to redirect its behavior.

Key Concerns

  • Unauthorized Data Exfiltration: extracting sensitive data without permission.
  • Unauthorized Actions: triggering an agent or connected tool to act outside its intended scope.
  • Remote Code Execution: running malicious code through the LLM or a connected tool.
  • Social Engineering: manipulating the model into behaving differently than planned.

FAQ

Direct injection is typed straight into the prompt by the user. Indirect injection is hidden in content the model reads as part of its normal operation, a webpage, document, or tool response, so the "attacker" never has to interact with the system directly at all.

Because the victim (the person using the AI tool) isn't the attacker. They may have no idea anything malicious happened, since the instruction came from content they trusted the system to process safely.


Share this page

Related Terms


Prompt Injection

Prompt injection is an attack where crafted input causes a large language model to deviate from its intended instructions and follow the attacker's instead.

Related Resources

Prompt Injection 101

AI Risks

Nov 3rd, 2024

Uncover real-world prompt injection examples and learn how these attacks work, why they’re hard to block & what you can do to protect AI systems.

Why AI Browsers Create a New, Unavoidable Security Risk

Agentic AI

Jan 22nd, 2026

AI browsers introduce structural security risks driven by prompt injection and autonomous actions. Learn why enterprises can't fully secure AI browsers, for now

Log In
Learn More
Book a Demo

Resources

Blog
AI Security Glossary
What is AI Security?
PromptCast: The Voice of AI & Security
ClawSec
OneClaw
Prompt Fuzzer
AI Security Startup Map
© {{year}} Prompt Security. All Rights Reserved.
Privacy Policy
Terms of Service

Follow Us