Indirect Prompt Injection: Every Channel, One Payload
A channel-by-channel reference for indirect prompt injection: web pages, HTML comments, CSV exports and email. Same payload, six ways in, and what to check.
3 write-ups tagged Indirect Prompt Injection. Browse all tags or the full blog.
A channel-by-channel reference for indirect prompt injection: web pages, HTML comments, CSV exports and email. Same payload, six ways in, and what to check.
LLM data exfiltration needs no script and no click. A markdown image is a silent outbound GET, and my own password reached my server in the query string.
I attacked my own AI support bot across all four layers. The guardrail held. The data, application and system layers all gave the attacker what he wanted.