T3Attacking AI Systems
Prompt Injection Fundamentals
How untrusted input becomes instructions, why the LLM can't tell data from commands, and the direct vs. indirect injection split that defines the attack surface.
Foundational2 min readfoundation streamUpdated Fri Jul 31 2026 00:00:00 GMT+0000 (Coordinated Universal Time)
Learning objectives
- Explain why an LLM cannot reliably separate instructions from data
- Distinguish direct from indirect prompt injection with a concrete example of each
- Map an application's trust boundaries onto its prompt assembly
Academy subscription
Subscribe to unlock this module
This module is part of the StrikeOps Academy subscription. Unlock every paid module, with hands-on labs and knowledge checks.
- Every paid module across all tracks
- Hands-on labs and knowledge checks
- New content as it ships
$59/ month · or $590 / year
The Reference library and Foundation starters are free to read now.