Definition
Prompt Injection
Prompt injection is an attack where malicious instructions are hidden in data the agent processes, such as an email or web page, and the model follows them as if they came from its operator. OWASP ranks it the top LLM risk. With filesystem or API access it becomes remote code execution. Defenses are unglamorous: least privilege, validating every tool argument, sandboxed execution, human approval for risky actions, and logging everything.
Explained in
Chapter 12: The Agent Toolbox
The protocols, tools, and infrastructure that make agents actually useful.
Related terms