T3Attacking AI Systems
Indirect and Cross-Domain Injection
Injection through content the model ingests: retrieved documents, emails, web pages, and tool output. Cross-domain and cross-tool confusion, dormant payloads, and the exfiltration channels that turn a read into a leak.
Intermediate3 min readassociate streamUpdated Sat Aug 01 2026 00:00:00 GMT+0000 (Coordinated Universal Time)
Learning objectives
- Explain how indirect injection plants instructions in content the model later reads
- Trace a cross-domain or cross-tool confusion chain across trust boundaries
- Identify realistic exfiltration channels once an injection lands
- Test whether ingested content is treated as data or as instructions
Academy subscription
Subscribe to unlock this module
This module is part of the StrikeOps Academy subscription. Unlock every paid module, with hands-on labs and knowledge checks.
- Every paid module across all tracks
- Hands-on labs and knowledge checks
- New content as it ships
$59/ month · or $590 / year
The Reference library and Foundation starters are free to read now.