What is indirect prompt injection through retrieved documents?
PICTURE THIS: AN LLM TURN
Simple meaning
An attacker poisons a wiki, email, or web page that your retriever will fetch.
WHY — Tokens instead of words?
LLMs use tokens (not full words) because it helps them:
who only read docs from people who shipped.
and tied to GenAI / LLM work.
Each piece maps to a number the network can learn.
Fixed pieces are what transformers expect as input.
STEPS — What happens step by step?
Before you speak the answer, walk the interviewer through these steps:
- 1An attacker poisons a
wiki, email, or web page that your retriever will fetch.
- 2Hidden instructions then run
with the privilege of your system prompt context.
- 3Mitigations include treating retrieved
text as data, instruction hierarchies, and output allowlists for tools.
- 4Give an example
One tiny concrete case you can say aloud.
- 5Common mistake
What juniors usually get wrong.
- 6Close
When you pick this over the alternative.
EXAMPLE — See it in action
Here's a short line you can speak, broken into clear beats:
Note: Adapt this scaffold to your own project — keep it under 60–90 seconds.
Key takeaway
An attacker poisons a wiki, email, or web page that your retriever will fetch. Hidden instructions then run with the privilege of your system prompt context.