# Indirect Prompt Injection

> Indirect prompt injection places malicious instructions inside content a model will later retrieve or process, such as a web page, email, or document, so the attack is triggered without the attacker interacting with the model directly.

- Identifier: PTL-0088
- Category: Security & Adversarial Prompting
- Canonical URL: https://protologue.com/t/indirect-prompt-injection/
- Introduced: 2023

## Description

Greshake et al. demonstrated that injected content could make integrated applications exfiltrate data, spread to other users, or manipulate outputs. Risk grows with an agent's access to tools and private data.

## Broader terms

- [Prompt Injection](https://protologue.com/t/prompt-injection/)

## Related terms

- [Retrieval-Augmented Generation](https://protologue.com/t/retrieval-augmented-generation/)
- [Spotlighting](https://protologue.com/t/spotlighting/)
- [AI Agent](https://protologue.com/t/ai-agent/)

## Sources

- Greshake et al. (2023). Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection. https://arxiv.org/abs/2302.12173

## Cite this entry

Protologue. (2026). Indirect Prompt Injection. In Protologue: A Taxonomy of Prompting and LLM Techniques (v1.0.0, PTL-0088). https://protologue.com/t/indirect-prompt-injection/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)
