CrawlCheck

Glossary · Security and privacy

Direct prompt injection

User-supplied text attempting to override application or system instructions. Refusal behavior helps but is not a complete authorization control.

Terms this definition uses

refusal

Security and privacy

Where an agent, a tool or a page can be turned against its operator, and the controls that limit the damage without proving safety.

Indirect prompt injection · Jailbreak · Data exfiltration · Sensitive information disclosure · Secret leakage · Insecure output handling · Excessive agency · Least privilege · Trust boundary · Input validation · Output validation · Allowlist · Denylist · SSRF · RCE · Credential scope · OAuth scope · API key · Bearer token · mTLS · Rate-limit policy · Audit log · PII · Data minimization · Purpose limitation · Retention period · Data residency · Tenant isolation · Threat model

Indirect prompt injection  ·  Jailbreak

See it in the full glossary · 579 terms across 19 areas. Scan a site to see which of these apply to it.