MITRE ATLAS 2026.09 / technique reference
AML.T0051.001
Indirect
MITRE source definition
An adversary may inject prompts indirectly via a separate data channel that the LLM or AI agent ingests, such as text or multimedia pulled from documents, emails, databases or websites. These instructions originate from adversary-controlled content rather than the legitimate user, and are frequently hidden or obfuscated (See [LLM Prompt Obfuscation](/techniques/AML.T0068)) from the user, for example as invisible text.
Adversaries may use this to hijack an agent or LLM in order to gain a foothold in the target system or to act against an unwitting user of that system, inheriting whatever privileges the AI system holds. Adversaries may also stage the lure that causes the content to be reached (See [AI Agent Clickbait](/techniques/AML.T0100)), or use the resulting foothold to establish persistence (See [AI Agent Context Poisoning](/techniques/AML.T0080)).
Indirect prompt injections have been observed in the wild, with potential impact ranging from harmless pranks, to search engine optimization manipulation, data exfiltration, and destructive actions.[[google-prompt-injections-web]]
Source modified 2026-09-15. Reproduced from the pinned ATLAS release; inline technique links resolve to local reference pages.
Parent, sub-techniques and ATT&CK references
Source-backed defensive context
MITRE mitigations
- AML.M0024 AI Telemetry Logging
- AML.M0033 Input and Output Validation for AI Agent Components
- AML.M0035 AI Red Team
MITRE case studies
- AML.CS0020 Indirect Prompt Injection Threats: Bing Chat Data Pirate · Exercise
- AML.CS0021 ChatGPT Conversation Exfiltration · Exercise
- AML.CS0026 Financial Transaction Hijacking with M365 Copilot as an Insider · Exercise
- AML.CS0029 Google Bard Conversation Exfiltration · Exercise
- AML.CS0035 Data Exfiltration from Slack AI via Indirect Prompt Injection · Exercise
- AML.CS0038 Planting Instructions for Delayed Automatic AI Agent Tool Invocation · Exercise
- AML.CS0039 Living Off AI: Prompt Injection via Jira Service Management · Exercise
- AML.CS0040 Hacking ChatGPT's Memories with Prompt Injection · Exercise
- AML.CS0045 Data Exfiltration via an MCP Server used by Cursor · Exercise
- AML.CS0046 Data Destruction via Indirect Prompt Injection Targeting Claude Computer-Use · Exercise
- AML.CS0048 Exposed ClawdBot Control Interfaces Leads to Credential Access and Execution · Exercise
- AML.CS0049 Supply Chain Compromise via Poisoned ClawdBot Skill · Exercise
- AML.CS0051 OpenClaw Command & Control via Prompt Injection · Exercise
- AML.CS0054 Data Exfiltration via Remote Poisoned MCP Tool · Exercise
- AML.CS0055 AI ClickFix: Hijacking Computer-Use Agents Using ClickFix · Exercise
- AML.CS0063 Prompt-Based Attacks Against Gemini via Calendar Invitations · Exercise
- AML.CS0066 ZombieAgent: Data Exfiltration Attack on ChatGPT · Exercise
- AML.CS0067 Claude Code GitHub Action Secret Exposure · Exercise
These are explicit source relationships, not independently reproduced incidents or validated detection coverage.
Simulation and telemetry boundary
This is a technique reference page, not a runnable simulation. No ATLAS-specific telemetry mapping, local attack execution or detector validation is asserted. MITRE maturity describes its source evidence, not a 1200km lab result.
For broader context—not technique-specific control mappings—see AI Security, AI Security Course, and detection-validation methodology.
Provenance and attribution
Immutable MITRE ATLAS source · Import provenance · Attribution and transformation notice · Apache License 2.0
Copyright 2021-2026 MITRE. Source text and explicit relationships are retained; navigation, formatting and local links are provided by 1200km.