Indirect prompt injection is a data-flow problem, not a prompt problem.
Teams spend months hardening the chatbot against direct attacks while the real risk sits in retrieved documents, ticket text and web pages that the model treats as instructions. We explain how we test it and which controls measurably reduce it.
- Injection delivered through retrieved help-centre content, not user input
- Downstream tool call reached an internal endpoint before the control