Glossary · Security and privacy
Indirect prompt injection
Malicious instructions embedded in content an agent retrieves or opens rather than typed by the user. Treating remote content as data, not authority, is the core boundary.
Security and privacy
Where an agent, a tool or a page can be turned against its operator, and the controls that limit the damage without proving safety.
Direct prompt injection · Jailbreak · Data exfiltration · Sensitive information disclosure · Secret leakage · Insecure output handling · Excessive agency · Least privilege · Trust boundary · Input validation · Output validation · Allowlist · Denylist · SSRF · RCE · Credential scope · OAuth scope · API key · Bearer token · mTLS · Rate-limit policy · Audit log · PII · Data minimization · Purpose limitation · Retention period · Data residency · Tenant isolation · Threat model
See it in the full glossary · 579 terms across 19 areas. Scan a site to see which of these apply to it.