SIGNAL//DESK
AI securitysrc: MITRE ATLAS

Triggered

A triggered prompt injection is like a hidden trap set by an attacker. Instead of you typing a bad command yourself, the attacker plants a 'landmine'—like a hidden instruction on a website or in a document—that your AI assistant accidentally reads and follows when it processes that information, causing it to do something you didn't intend.

Triggered prompt injection occurs when an adversary embeds malicious instructions within a victim's environment, such as a web page or document, which an AI agent subsequently processes. The injection is 'triggered' when the agent interacts with this content, allowing the adversary to bypass security controls or manipulate the agent's behavior without direct user input at the moment of execution.

An adversary may trigger a prompt injection via a user action or event that occurs within the victim's environment. Triggered prompt injections often target AI agents, which can be activated by means the adversary identifies during Discovery (AML.TA0008) and Activation Triggers (AML.T0084.002). These malicious prompts may be hidden or obfuscated from the user and may already exist within the victim's environment via Prompt Infiltration via Public-Facing Application (AML.T0093), enabling the adversary to gain a foothold or target an unwitting user.

seen in events


← all terms