Indirect Prompt Injection: Every Channel, One Payload
A channel-by-channel reference for indirect prompt injection: web pages, HTML comments, CSV exports and email. Same payload, six ways in, and what to check.
3 write-ups tagged AI Penetration Testing. Browse all tags or the full blog.
A channel-by-channel reference for indirect prompt injection: web pages, HTML comments, CSV exports and email. Same payload, six ways in, and what to check.
I mapped a database through a text-to-SQL chatbot without writing a line of SQL. Why LLM SQL injection is an authorisation failure, not an injection bug.
I ran eight prompt-leak payloads at an input blocklist and an output redactor. One got blocked. A system prompt is not a secret store, and here are the numbers.