← Back to glossaryGlossary

Indirect Prompt Injection

Reviewed 19 July 2026Canonical definitionPart of: AI Agent Fundamentals →

Indirect prompt injection is an attack where malicious instructions are embedded in data the agent retrieves, such as documents, emails, or web pages, rather than in the user's direct input. It is one of the hardest agent threats to defend against.

§01 / QUESTIONSterm: Indirect Prompt Injection
Questions

Common questions.

What is Indirect Prompt Injection?

Indirect prompt injection is an attack where malicious instructions are embedded in data the agent retrieves, such as documents, emails, or web pages, rather than in the user's direct input.

How does Indirect Prompt Injection work?

It is one of the hardest agent threats to defend against.

Which terms are related to Indirect Prompt Injection?

Closely related concepts include Spec-Driven Development, System Prompt, Agentic Coding, OWASP Top 10 for LLM Applications. Each is defined in the Prefactor glossary.

§02 / RELATEDnext: where this fits
Keep reading

Where this fits.

See how every agent performs, and make it better

Prefactor helps teams observe, evaluate, and improve their AI agents in production, across every framework and provider.