Topic · DiggingBeagle record

Indirect prompt injection

Untrusted external content influences an agent's instructions through retrieval, browsing or tool output.

Topic kind
pattern

Definition & limits

The security question is not only whether a model follows hostile text. The important reconstruction is what downstream tool, credential or control plane can turn that influence into an action.

Examples

  • A malicious web page steers a browsing agent toward a local MCP endpoint.
  • A model-controlled search parameter reaches an unsafe eval sink.

Research using this topic (3)

Cite this record

DiggingBeagle. “Indirect prompt injection.” https://diggingbeagle.com/concepts/indirect-prompt-injection/

Citation guidance

Why this archive exists

The source matters after the headline fades.

DiggingBeagle is a non profit research project documenting AI security incidents, agent failures, vulnerabilities and AI-assisted operations. A case keeps its claims beside the sources that support, contest or limit them. Later updates stay visible, so a reader can see when the account changed.

We publish case reconstructions, dated reporting and analysis across records. Each has a different evidentiary role. About the project and our methodology explain how the work is reviewed.