AI security
Prompt injection
Also called: indirect prompt injection, LLM prompt injection
Prompt injection is an attack in which content the model reads is crafted to be followed as instruction. In the indirect form, the malicious text arrives inside a document, web page, email or tool response rather than from the user, which is what makes it a supply chain problem for AI features.
It becomes a security vulnerability rather than a curiosity at the point the model has authority: tools it can call, data it can read, actions it can take. The risk is the path from attacker-controlled instruction to a sensitive operation.
See also
Testing, with the report an auditor can actually use
A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.