S0119RS3-T10-S0119-Z · Full risk code

Indirect Prompt Injection Hijacking the System

間接提示注入劫持系統

Verification & Validation
Risk Description

When an organization's email assistant reads an incoming message containing hidden instructions and automatically forwards internal data to an external address; due to unmitigated control gaps, the user merely received a normal email and noticed nothing unusual, triggering external stakeholder impacts and causing the incident is discovered only through audit log comparison.

Framework Mappings

OWASP Top 10 for LLMLLM01
MITRE ATLASAML.T0051
NIST AI 600-1Information Security
ISO/IEC 5338運作與監控
MIT AI Risk RepositoryDomain 2

Risk Treatment & Implementation Guidance

Apply trust tiers to external content so instructions inside untrusted material like email are never executed as system directives; Detect hidden content, identifying embedded instruction patterns in messages and documents; Restrict exfiltration-capable actions like auto-forwarding with policy limits and human confirmation so agents cannot send internal data externally on their own