Skip to content
← LibraryTechnique entry
AI-INDIRECT-INJECTInitial Access

Indirect Prompt Injection (RAG / Web)

Malicious content lives in a document, web page, or PDF that the LLM later ingests via RAG / browse tools — injection fires when the model reads it.

§ Where this technique fits

AI-INDIRECT-INJECT is catalogued under the Initial Access tactic of the offensive-security kill-chain. It appears in 3 approved dossiers in the registry, typically at step 3 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Tool / Function-Call Abuse
    AI-TOOL-ABUSE · Execution
    seen 3×