Prompt injection

If your AI agent reads a text, that text can give it orders.

Request a consultation

What it is

Prompt injection is an attack on language models (LLMs): an instruction hidden in an email, web page or document is read by the assistant or AI agent as if it were a legitimate command. It can push it to reveal data, send messages or perform actions the user did not ask for.

How it works

  1. 1The attacker places instructions in content the agent will read: hidden text, comments, metadata.
  2. 2The agent reads the content together with your requests and does not always tell what is data and what is an order.
  3. 3If it has access to email, files or tools, it can send data out or perform actions.
  4. 4The more permissions the agent has, the worse the possible damage.

How to spot it

  • The assistant does things you did not ask for or cites instructions you did not give
  • Links or images with data in the address generated by the agent
  • Unrequested actions on email, files or payments
  • Different behaviour after reading a certain page or document

How to defend

  • Give agents only the strictly necessary permissions (least privilege)
  • Always require human confirmation for sensitive actions: sending, payments, deletions
  • Treat all external content as untrusted and keep it apart from sensitive data
  • Check and limit the addresses and tools the agent may use
  • Log and monitor actions, and test the system with attack exercises

If you think you have been hit

  • Revoke the agent’s tokens and keys at once and rotate secrets
  • Check the logs to see which actions it performed
  • Reduce permissions before turning it back on

And there are many, many more

The attacks above are only some of the most common: there are hundreds, and new ones appear every week. If the one that concerns you is not among them, write to me: I will tell you whether it really affects you and how to defend.

Contact me

Other attacks

Watch the Shorts on YouTube

Matteo Russo · Updated October 2026

Let's talk
no strings attached

Want to know how exposed you are, train your team, or just ask a question? Write to me: I reply personally.

  1. You writeA couple of lines about your case: person, company, doubt or request.
  2. We talkA short intro call to understand what you really need.
  3. Practical defenseAssessment, consulting or training, with clear, prioritized actions.

Request a consultation

For security, the email address is not written on the page: press the button to reveal it and copy it in one click.

For companies and individuals. No scaremongering, just practical defense.