The attack via retrieved content. This lesson sits inside Module I — The attack — of Prompt Injection, the course that anchors the AI Security program. It is not a survey; it is the specific, working understanding of "Indirect prompt injection" that the rest of the course assumes you carry forward.
- 01Define Indirect prompt injection in the precise sense used across Prompt Injection.
- 02Recognize when Indirect prompt injection is the correct lens for the situation in front of you, and when it is not.
- 03Apply Indirect prompt injection to a concrete case drawn from The attack, and defend the result in plain language.
- 04Connect Indirect prompt injection to the adjacent lessons in this module without collapsing the distinctions between them.
The idea, stated plainly
The attack via retrieved content. That single sentence is the whole lesson in compressed form. The rest of the reading unfolds it — what it means when the terms are taken seriously, where it comes from, and what work it does inside Prompt Injection. Read the sentence, then read it again after the sections below; it should carry more weight the second time.
Why it belongs in The attack
Module I exists because how it works. "Indirect prompt injection" is one of the pillars of that module: without it, the later lessons either become memorization or lose their bite. Notice which earlier lessons this one leans on, and which later lessons will lean on it — the shape of the module is easier to see once you place this piece.
How the School of Artificial Intelligence faculty use it
In practice, working school of artificial intelligence professionals reach for this idea before they reach for a formula or a tool. It is a way of framing the problem so that the right question comes first. The mark of understanding is not that you can recite Indirect prompt injection; it is that you catch yourself using it, unprompted, when the situation calls for it.
Common misreadings
The most frequent error is to treat Indirect prompt injection as a slogan and skip the mechanics. The second most frequent is the opposite — treating the mechanics as the point, when the mechanics are only there to make the idea usable. Both errors collapse the same distinction, and both are correctable by returning to the one-line summary and asking what it actually claims.
- Indirect prompt injection is a working tool, not a slogan.
- Its meaning is set by the module it lives in: The attack.
- Understanding is demonstrated by unprompted use in the correct situation.
- The adjacent lessons in this module are its natural context; read them together.
- 801 — Prompt Injection, Module I: The attack — The parent module for this lesson. Re-read the module blurb after finishing the lesson.
- The Anabasis Academy — School of Artificial Intelligence, AI Security — The wider program this lesson serves; the Certificate in AI Security (Practitioner tier). credential ultimately certifies mastery of ideas like this one.