M29.5 CONNECT THE MECHANISM
Protect tools and sensitive data around the model
An accounting assistant writes SQL, renders HTML, and reads suppliers' PDFs. Every one of those is a door. Learn to treat the model's output the way you'd treat a stranger's.
LESSON OVERVIEW12 min lesson
Lesson overview
An accounting assistant writes SQL, renders HTML, and reads suppliers' PDFs. Every one of those is a door. Learn to treat the model's output the way you'd treat a stranger's.
What you’ll explore
- Language-model application security depends on trust boundaries, least-privilege tools, output handling, and data isolation; prompt injection exploits confusion between external content and authorized instructions.
GO TO THE SOURCE
Original explanations, connected to the research.
Not What You've Signed Up For: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection (Greshake et al., 2023)OWASP Top 10 for Large Language Model Applications (2025)Prompt injection attacks against GPT-3 (Simon Willison, September 2022)Prompt injection and jailbreaking are not the same thing (Simon Willison, March 2024)NIST AI Risk Management FrameworkSuggest a correction
A precise note can make an explanation better.
Choose the scene and describe what needs attention. Download a feedback file to share through a channel you already use. This page does not send feedback or connect you with a reviewer.