AML.T0051.001LLM Prompt Injection: Indirectview on ATLAS ↗Adversary injects prompts via a separate data channel ingested by the LLM (databases, websites, documents) rather than directly in user input.
Agentic angle: Primary injection vector for RAG-backed agents: malicious text in retrieved context becomes instructions the model follows silently.