Global site search

Search guides, labs, glossary, and research

Type two or more characters to search.

Start with a channel, artifact, or defense term

Examples include zero-width, metadata, tokenizer, or prompt injection.

    Global search

    Find a channel, demo, defense, or research report.

    Search the site’s hand-curated index. Results stay on MachineTradecraft.com and no query is sent to a third party.

    15 results for “prompt injection”.

    Search results for “prompt injection”

    Result summaries are bounded excerpts. The match label explains whether the query appeared in the title, summary, indexed topics, or content type.

    1. Research report Title, summary, and topics match Indirect Prompt Injection, Retrieval Poisoning, and Agent Trust Boundaries A defense-in-depth analysis of direct and indirect prompt injection, retrieval poisoning, tool scopes, credentials, memory, transaction confirmation, output validation, egress, detection, incident response, and…
    2. Defense Title and topics match Indirect Prompt Injection Defense Preserve evidence, compare representations, canonicalize input, retain provenance, and separate privilege.
    3. Glossary term Title match Indirect prompt injection Instructions entering an AI system through external content—such as a webpage, email, or document—rather than through the direct trusted instruction channel.
    4. Research report Title match The Anatomy of Indirect Prompt Injection Threat models, retrieval, concealment, action amplification, instruction hierarchy, dual-model isolation, and execution monitoring.
    5. Research report Summary and topics match Email, MIME, Calendar, and Collaboration Metadata as Machine-Readable Channels A structural analysis of Internet Message Format, MIME nesting, alternative bodies, authentication claims, remote resources, iCalendar actions, collaboration metadata, indirect prompt injection, and safe offline parsing.
    6. Research report Summary and topics match Multimodal Machine Perception: Pixels, OCR, Alternative Text, Metadata, and Visual Instruction Security A detailed analysis of pixels, alpha, compression, OCR, alternative text, metadata, QR-like symbols, multimodal prompt injection, adversarial images, provenance, safe ingestion, and accessibility.
    7. Topic guide Summary and topics match Retrieval and Agent Trust Boundaries Model indirect prompt injection as an application trust-boundary failure across retrieval, context assembly, tools, credentials, memory, output, and egress.
    8. Interactive lab Topics match Accessibility Metadata Inspector Extract alt text, aria-label, aria-labelledby, titles, hidden labels, and visible text into separate provenance-labelled views.
    9. Interactive lab Summary and topics match Controlled Benign Instruction-Uptake Lab Create fixed-marker carriers, inspect extraction separately from uptake, and copy an analysis-first prompt for an authorized AI test environment.
    10. Topic guide Topics match Document Metadata and AI Trace PDF, Office, image, JSON, and XML fields outside the primary visible content.
    11. Topic guide Topics match Hidden HTML Text and AI Compare DOM nodes, rendered text, comments, CSS state, and accessibility fields.
    12. Interactive lab Topics match Local Retrieval & RAG Trust-Boundary Simulator Rank a small local corpus, show retrieved documents and metadata, assemble model context, and locate a fixed benign marker.
    13. Topic guide Topics match Multimodal Machine Perception Security Compare pixels, alpha, scaling, OCR, alternative text, captions, metadata, symbols, provenance, and model-facing visual instructions.
    14. Interactive lab Topics match Retrieval and Agent Trust-Boundary Simulator Compare deterministic application-layer outcomes for source labelling, instruction/data separation, tool allowlisting, human confirmation, egress filtering, and bounded memory using a fixed harmless marker.
    15. Research report Summary match Browser Automation, Accessibility Trees, and Agent-Facing Web Representations A detailed treatment of WebDriver, CDP, live DOM state, accessibility mappings, accessible names, geometry, screenshots, locators, timing, dialogs, prompt injection, capability safeguards, and semantic testing.