Direct injection is typed straight into the prompt by the user. Indirect injection is hidden in content the model reads as part of its normal operation, a webpage, document, or tool response, so the "attacker" never has to interact with the system directly at all.