I · D3 · 3.1
Indirect prompt injection
Malicious instructions hidden in documents, emails, web pages the model reads.
Major · 4Documented at scaleNowRisk 20
Severity
4/5
Likelihood
5/5
In the hierarchy
- Part I: Technical & System Concerns
- D3. Security & Adversarial Risk
- 3.1 Prompt injection & jailbreaks
Virtues and principles to explore
Held as inquiry, not as a verdict.
Stewardship
Service
Hold what is built in trust for those who will live with it.
Prudence
Excellence
Small, reversible steps before irreversible ones.
Accountability
Trust
Name who holds the consequence before it is needed.
Starter questions
Written to probe curiosity and learning, not accusation.
- 01What would Accountability require of us here, before we proceed?
- 02What might we be missing if we treat “Indirect prompt injection” only as a technical problem?
- 03If a colleague raised this concern tomorrow, how would we receive it as inquiry rather than accusation?
- 04What capacity would we need — in people, in the institution, in the tools — to meet this well?
Also on this branch
Frameworks and sources
- OWASP GenAI LLM Top 10 (2026)framework
- MITRE ATLASframework
Writing and incidents
Open indexes first. Then, if you wish, ask Grok to search the live web for this concern — one request, cached for the rest of this session.
Attacks on and through AI systems: injection, jailbreaks, cyber offense.