Prompt injection occurs when external or embedded instructions override the intended control of a language model. In agents, this can lead directly to access to tools, data, or external systems.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
Concrete cog in the system that works inside larger relationships.
A prompt injection is an input that induces a language model to bypass its original instructions or perform sensitive actions.
The term emerged with the practical use of instruction-following language models and was shaped by early attacks on chatbots and LLM applications; OWASP now treats prompt injection as a central LLM application risk.
Instructions and data share one text channel. An injected instruction masquerades as data, shifts the model's priorities, and can influence responses, tool calls, or data access.
The term captures this component’s central purpose and key decision.
The model processes untrusted instructions in context and may mistakenly give them precedence over the intended task.
Protection combines separated trust boundaries, least privilege, filtering, and human approval for risky actions.
Prompt-injection protection matters especially in RAG systems, agents, and tool calls. Trust boundaries and approvals limit impact, but a single filter cannot eliminate semantic manipulation completely.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.