Reproducing indirect prompt injection against a RAG pipeline
A controlled experiment showing how instructions planted in retrieved documents can cross the data boundary and influence a model.
2026-04-21 · 10 min readRead postResearch and implementation notes on prompt injection, retrieved context, tool actions, and the operational work around them.
A controlled experiment showing how instructions planted in retrieved documents can cross the data boundary and influence a model.
2026-04-21 · 10 min readRead postWhy prompt injection is a trust-boundary problem, and what runtime inspection can honestly do about it.
2026-04-14 · 7 min readRead postA practical operating guide for provenance, retrieved-context inspection, least privilege, and evidence.
2026-03-18 · 8 min readRead postThe risk changes when a model can read private data, consume untrusted content, and communicate or act outside the system.
2026-04-29 · 8 min readRead postThe product changed, but the core concern did not: untrusted language should not quietly become trusted behaviour.
2026-03-02 · 5 min readRead post