MITRE ATLAS 2026.09 / technique reference
AML.T0093
Prompt Infiltration via Public-Facing Application
MITRE source definition
An adversary may introduce malicious prompts into the victim's system via a public-facing application with the intention of it being ingested by an AI at some point in the future and ultimately having a downstream effect. This may occur when a data source is indexed by a retrieval augmented generation (RAG) system, when a rule triggers an action by an AI agent, or when a user utilizes a large language model (LLM) to interact with the malicious content. The malicious prompts may persist on the victim system for an extended period and could affect multiple users and various AI tools within the victim organization.
Any public-facing application that accepts text input could be a target. This includes email, shared document systems like OneDrive or Google Drive, and service desks or ticketing systems like Jira. This also includes OCR-mediated infiltration where malicious instructions are embedded in images, screenshots, and invoices that are ingested into the system.
Adversaries may perform Reconnaissance to identify public facing applications that are likely monitored by an AI agent or are likely to be indexed by a RAG. They may perform [Discover AI Agent Configuration](/techniques/AML.T0084) to refine their targeting.
Source modified 2026-05-27. Reproduced from the pinned ATLAS release; inline technique links resolve to local reference pages.
Parent, sub-techniques and ATT&CK references
No explicit relationship in this pinned source.
Source-backed defensive context
MITRE mitigations
MITRE case studies
- AML.CS0016 Achieving Code Execution in MathGPT via Prompt Injection · Exercise
- AML.CS0026 Financial Transaction Hijacking with M365 Copilot as an Insider · Exercise
- AML.CS0029 Google Bard Conversation Exfiltration · Exercise
- AML.CS0037 Data Exfiltration via Agent Tools in Copilot Studio · Exercise
- AML.CS0038 Planting Instructions for Delayed Automatic AI Agent Tool Invocation · Exercise
- AML.CS0039 Living Off AI: Prompt Injection via Jira Service Management · Exercise
- AML.CS0040 Hacking ChatGPT's Memories with Prompt Injection · Exercise
- AML.CS0046 Data Destruction via Indirect Prompt Injection Targeting Claude Computer-Use · Exercise
- AML.CS0059 EchoLeak: Zero-Click Prompt Injection Targeting M365 Copilot for Data Exfiltration · Exercise
- AML.CS0060 Cross-Site Scripting via Prompt Manipulation in Lenovo AI Chatbot · Exercise
- AML.CS0063 Prompt-Based Attacks Against Gemini via Calendar Invitations · Exercise
- AML.CS0066 ZombieAgent: Data Exfiltration Attack on ChatGPT · Exercise
- AML.CS0067 Claude Code GitHub Action Secret Exposure · Exercise
These are explicit source relationships, not independently reproduced incidents or validated detection coverage.
Simulation and telemetry boundary
This is a technique reference page, not a runnable simulation. No ATLAS-specific telemetry mapping, local attack execution or detector validation is asserted. MITRE maturity describes its source evidence, not a 1200km lab result.
For broader context—not technique-specific control mappings—see AI Security, AI Security Course, and detection-validation methodology.
Provenance and attribution
Immutable MITRE ATLAS source · Import provenance · Attribution and transformation notice · Apache License 2.0
Copyright 2021-2026 MITRE. Source text and explicit relationships are retained; navigation, formatting and local links are provided by 1200km.
No explicit relationship in this pinned source.