Also called: indirect injection
Hiding instructions inside content a model will read - a webpage, an email, a PDF - to hijack what it does next.
Why it mattersThe top security risk for agents. If your agent reads untrusted text, assume it can be talked into things.
See also Guardrails, Jailbreak