Skip to content
Glossary · Industry term

Indirect prompt injection

Also known as: IPI, second-order prompt injection

Prompt injection delivered via content the LLM retrieves rather than via the user's direct prompt — a poisoned web page, email, document, or tool response that the agent ingests and treats as instructions.

How this publication uses it

Indirect injection is the more dangerous variant for agentic systems because the attacker never speaks to the user. Any tool that pulls untrusted content (web fetch, email read, document parse) becomes an attack surface. EchoLeak-class cross-agent variants compound this: one agent's output becomes another agent's untrusted input.

Related frameworks

Articles that analyse this term

Primary sources

Vigil · 70 reviewed