Skip to content
Wingback Security

Glossary

Prompt injection

Updated

An attack that hides instructions in content an AI model or agent will read (a document, a web page, a tool result) to hijack its behaviour. Indirect prompt injection rides on retrieved or third-party data. The dangerous part is usually the downstream action the injected instruction triggers, such as exfiltrating data or misusing a tool.