Indirect Prompt Injection Leading to Unauthorized Agent Tool Execution
- Scenario
- A malicious instruction inside an untrusted document enters the RAG context.
- Attack
- The agent reads retrieved content as trusted instruction.
- Potential Impact
- Unauthorized tool execution and data exposure.