← Back to glossary Glossary

Context Window Poisoning

Reviewed 19 July 2026 Canonical definition Part of: MCP & Agent Protocol Terms →

Context window poisoning is an attack in which malicious content is injected into an agent's input context, through a retrieved document, a tool response, or a prior conversation turn, with the intent of overriding the agent's instructions or causing it to take harmful actions. It is a variant of indirect prompt injection that targets the context assembly layer rather than the system prompt directly.

§01 / QUESTIONSterm: Context Window Poisoning
Questions

Common questions.

What is Context Window Poisoning?

Context window poisoning is an attack in which malicious content is injected into an agent's input context, through a retrieved document, a tool response, or a prior conversation turn, with the intent of overriding the agent's instructions or causing it to take harmful actions.

How does Context Window Poisoning work?

It is a variant of indirect prompt injection that targets the context assembly layer rather than the system prompt directly.

Which terms are related to Context Window Poisoning?

Closely related concepts include MCP Poisoning, AI Firewall, MCP Server Discovery, Rug Pull Attack (MCP). Each is defined in the Prefactor glossary.

§02 / RELATEDnext: where this fits
Keep reading

Where this fits.

See how every agent performs, and make it better

Prefactor helps teams observe, evaluate, and improve their AI agents in production, across every framework and provider.