← Prompt Injection SecurityCONTENT HISTORY

Update to Prompt Injection Security

Snapshot Sep 30, 2026 · 23:17 UTC · version 0.1.0

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "indirect-injection-review",
  "description": "Examine documents, web pages, retrieval chunks, messages, and multimodal inputs as possible indirect prompt-injection sources.",
  "included_files": [
    {
      "relative_path": "._SKILL.md",
      "size_in_bytes": 163
    }
  ],
  "skill_md_contents": "---\nname: indirect-injection-review\ndescription: Examine documents, web pages, retrieval chunks, messages, and multimodal inputs as possible indirect prompt-injection sources.\n---\n\n# Untrusted Content and Indirect Injection\n\nApply when an AI system reads externally authored or user-controlled content, including RAG records, webpages, email, tickets, source repositories, images, or tool output.\n\n## Process\n\n1. Inventory content sources, provenance, transformation/extraction steps, retrieval filters, trust labels, and destinations in the model context.\n2. Look for instruction-like content, hidden or rendered text, metadata, encoding/normalization edge cases, content poisoning, and cross-modal discrepancies. Treat indicators as leads, not automatic proof.\n3. Trace whether external content can influence a privileged assistant, persistent memory, tool choice/arguments, downstream content rendering, or other users' contexts.\n4. Check whether untrusted text is explicitly separated and labeled, whether summaries preserve provenance, and whether actions are independently authorized from original user intent.\n5. Recommend a quarantine or data-only path, provenance and citation retention, least-privilege processing, safe parsers/renderers, retrieval isolation, and regression fixtures tailored to evidence.\n\n## Output\n\nProvide source/entry point, boundary crossed, evidence, reachable impact, confidence, safe sample test, mitigations, and unexamined areas. Do not fetch arbitrary links or decode content if doing so would access private endpoints or transmit sensitive data. Ask for supplied artifacts or use a clearly authorized public target.\n"
}

SHA-256: 44c772ffc8b3dbde6d6f393e8c920320a441c536fe5a951be029a648ea0a5ea9