Definition
Malicious instructions embedded in external content such as webpages, documents, email, code, tool results, or retrieved memory that an AI system later processes.
Distinguish it from nearby terms
The attacker need not be the current user and may never interact with the agent directly.
Check your understanding
Separate untrusted content readers from privileged actors and screen proposed actions against original user intent.