Look twice.Find the gem.

AI agents and MCP servers, each published with its source and what the checks found.

Marketplace

  • Everything
  • AI agents
  • Apps
  • MCP servers
  • Templates
  • What people want
  • What changed this week
  • The verification standard
  • The ooruby Index
  • Servers that publish no source
  • Reliability guides
  • What the catalogue holds
  • Sell here

Our library

  • Everything, in one place
  • Guides
  • Glossary
  • Calculators
  • Checklists and cheat sheets
  • Community

ooruby

  • Home
  • For teams
  • Site status
  • Company projects
  • RSS feed

Verification records what our published tests found on a specific version at a specific date. It is not a warranty, and it does not certify that software is free of defects.

Rubricv1.0
AI agentsAppsMCP serversTemplatesWantedCommunityOur library
Sign inSell
Glossary
Security findings

Indirect prompt injection

Instructions planted in content a model reads while working, such as a web page, an email or a tool's output, rather than typed by the user.

The user asks for something ordinary, the agent reads a document or calls a tool to do it, and the text that comes back contains instructions. The model cannot reliably tell data it was given from instructions it should follow, so it may act on them.

Tool descriptions are one channel and tool outputs are another. A server can hand back a result with instructions in it, which a description scanner will never see, because the description was clean.

Why it matters

It means an agent is only as safe as the least trustworthy text it reads, and it is the reason a clean tool description is not the same thing as a safe tool.

The mistake everyone makes

Defending only the prompt the user types. The injection arrives in the material the agent was asked to process.

Related terms

Prompt injection
Getting a model to follow instructions that arrive inside data it was asked to process.
Tool poisoning
Hiding instructions inside a tool description so the model reads them as commands.
Data exfiltration
Moving data out of a system to somewhere its owner did not intend.
Human in the loop
Requiring a person to approve a specific class of action before an agent takes it.
Previous
Human in the loop
Next
Invisible characters

See Indirect prompt injection on a real listing

Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.

Open the catalogue