What is indirect prompt injection, and why is it so dangerous for RAG and agents?
With direct injection the user attacks the prompt. With indirect injection the payload sits inside a page, doc, or email the model reads. The signal is recognizing that retrieved and tool data is untrusted and can hijack the model. Here is the answer.
Updated Sep 2026 · Grounded in real GenAI, LLM, and AI/ML engineering interview loops and written to a senior-engineer editorial bar.
With direct injection the user attacks the prompt. With indirect injection the payload sits inside a page, doc, or email the model reads. The signal is recognizing that retrieved and tool data is untrusted and can hijack the model. Here is the answer.
Lead with where the obvious approach breaks, because that is the judgment they are screening for — most candidates jump straight to the happy path and lose the room.
Then walk the failure back through the pipeline in order, naming the one metric the customer's exec sponsor actually cares about before you propose the fix.