What is an example of an indirect prompt injection?
An indirect prompt injection example has four hops. A stranger writes the text. A store keeps it. An agent reads it while doing a normal job. A tool then sends something out. The box below is not an order. [PLACEHOLDER INSTRUCTION] only marks the slot.
- Write. Someone fills a public form. The message is a real question plus the marker.
- Store. The form backend saves the fields. It can also mail or chat a copy. The text is still data.
- Read. Later, a person asks an agent to summarize new leads. A tool returns the stored message.
- Send. The agent treats the marker as an order and proposes a mail or a link. A safe host does not send unless a person and the server both allow that exact call.
That is one llm prompt injection attack example. The attacker never opens the chat. The agent meets the text because someone asked for a summary. Direct injection is the other shape. The person types the attack into the live chat. Indirect prompt injection in MCP is the definition. This page is the dated list.
Primary sources were fetched again on 06.10.2026. A number that is not in those pages is not here. Every sample uses the same marker, or the domain attacker.example.
name: Ada email: ada@example.com message: Please quote the patio. [PLACEHOLDER INSTRUCTION]
Indirect prompt injection attack examples
These are the indirect prompt injection attack examples we could verify on 06.10.2026. Prompt injection examples 2026 are the last rows. The direct EmailGPT row is labeled so it is not mixed in. The Claude Code row is telemetry, not an injection case. It is here because approval prompts fail often.
| Date | Product | Channel | Sink | CVE / score | Fix | Source |
|---|---|---|---|---|---|---|
| 23 Feb 2023 | Bing Chat | Web page | Data theft, API choice, worming | None | Strong fixes were lacking | Greshake et al. |
| 8 Jun 2023 | 36 live apps (HouYi) | App content | Prompt theft, open model use | None. 31 of 36 failed their test | 10 vendors confirmed, including Notion | Liu et al. |
| CVE record | EmailGPT | Direct chat (contrast) | System prompt leak | CVE-2024-5184. CVSS 3.1 is 6.5. CVSS 4.0 is 8.5 | Direct, not indirect. Scores are the CNA’s | CVE-2024-5184 |
| 26 May 2025 | GitHub MCP | Public issue | Public pull request | None. Not a server bug | One repo per token | Invariant Labs |
| 11 Jun 2025 | Microsoft 365 Copilot | Image URL via a Teams address the page allowed | CVE-2025-32711. CNA CVSS 3.1 is 9.3 (critical) | Rolled out by 11 June 2025. No customer hit | Aim Labs. Email chain | |
| 10 Jul 2025 | Gemini for Workspace | Summary text, not an auto send | None in the post | Hidden text still worked that day | 0DIN | |
| 2 Sep 2025 | Shortwave | A link, plus saved memory | None | Show memory edits. Confirm links. Harder system prompt | Insinuator | |
| 8 Sep 2025 | Salesforce Agentforce | Web-to-Lead form | Image request to an expired allow-listed domain | No CVE. Noma scored 9.4 | Trusted URLs on 8 Sep 2025. Domain taken back | ForcedLeak |
| Dec 2025 | An ad-review agent | Web page | A review verdict | None | Page text must not set the verdict | Unit 42 |
| 15 Jan 2026 | Copilot Studio | SharePoint form | CVE-2026-21520. CVSS 3.1 is 7.5 (high) | Fix 15 Jan 2026. CVE date 22 Jan 2026 | ShareLeak | |
| 15 Apr 2026 | Salesforce Agentforce | Lead form | None | Stock email needs a person | PipeLeak | |
| 25 May 2026 | Claude Code | Permission prompt (not an injection) | The approval click | None | Containment. Users approved about 93% of prompts | Anthropic |
What is EchoLeak?
EchoLeak is CVE-2025-32711. The CVE record calls it AI command injection in Microsoft 365 Copilot. An attacker with no login can disclose information over a network. The CNA score is CVSS 3.1 base 9.3, critical. Aim Labs describe a zero-click chain. A crafted email enters retrieval. The sink is an image URL on a Teams address the page already allowed. This page does not print that address. Simon Willison’s 11 June 2025 note says the report was in January and the fix was already rolled out. Microsoft confirmed no customer was affected. The email mechanics are in Indirect Prompt Injection via Email.
Indirect prompt injection in the wild
Unit 42’s 15 December 2025 note is indirect prompt injection in the wild for LLM systems. Hidden text on a live page aimed at an AI ad reviewer, to get a scam ad approved. Their longer article calls it their first case of that kind. There is no CVE. The sink is a verdict the model must not set.
The direct row, for contrast
CVE-2024-5184 is EmailGPT, and it is direct. A user can leak hard-coded system prompts or run unwanted prompts. The CNA lists CVSS 3.1 at 6.5 and CVSS 4.0 at 8.5. The row keeps the two shapes apart.
Prompt injection through web forms: ForcedLeak, PipeLeak, and ShareLeak
A public form is a channel anyone can write. The CRM stores the text. An agent reads it when a person asks for a summary. If that agent can mail or open a link, the form is an order slot.
ForcedLeak: Agentforce prompt injection through Web-to-Lead
Noma Labs published ForcedLeak on 25 September 2025. Sasi Levi describes a chain in Salesforce Agentforce. Noma scored it CVSS 9.4 and called it critical. The post does not name a CVE.
Web-to-Lead lets a stranger submit a lead. Description holds 42,000 characters. Shorter fields were too small. The text waits. Nothing runs at submit time. The agent runs when an employee asks about the lead. Noma’s sample is a normal sales task: check this lead and draft a reply. Agentforce then reads the stored description. It also answered a question that had nothing to do with CRM data.
The sink was an image request, not a mail. The image host was a domain Salesforce already allowed. That domain had expired, and Noma bought it. The image load carried CRM answers to Noma’s server. Noma lists contact details, pipeline notes, and older interaction records as the data at risk. Any org that let Agentforce read Web-to-Lead rows was in range.
Noma reported it on 28 July 2025. Salesforce replied on 31 July 2025. On 8 September 2025 Salesforce turned on Trusted URLs for Agentforce and Einstein AI, and took the expired domain back. Agent output could no longer go to an untrusted URL. Treat Description as data. Do not let the agent build a link from lead text.
PipeLeak: a second Agentforce lead form
Capsule Security disclosed PipeLeak on 15 April 2026. They reported it in December 2025. Salesforce acknowledged it in January 2026 and answered in February 2026. The post names no CVE and no score.
A public form saved name, email, company, and a free-text help field onto the Lead object. One flow read lead rows. One flow sent mail. The agent user could read Lead, including Description. The attacker files one lead. An employee later asks the agent to review it. The agent reads the stored field, can pull more leads than that one row, and mails them. No login is required to file the lead. CSO Online covered both form bugs the same day.
Salesforce’s reply, as Capsule quotes it, splits the issue. Prompt injection was still with product security. Mail through custom actions was called a configuration issue, not a platform flaw. Stock email actions need a person in the loop. Custom actions can use the same gate. Capsule answers that people enable agents so mail goes out with no click. The stop does not depend on that debate. An agent that reads a public lead must not hold an email tool. If mail is required, a person must see the real recipient and the real body. The server must refuse any other address. Capsule’s timeline shows no platform patch for the injection itself.
ShareLeak: Microsoft Copilot Studio prompt injection
ShareLeak is CVE-2026-21520 in Copilot Studio. A public SharePoint form’s Comments field was copied into the agent prompt. The agent read a connected list and mailed the rows. Capsule says safety checks flagged the request, and the data still left. The mail used a normal Outlook action, so data-loss rules did not fire.
The CVE title is “Copilot Studio Information Disclosure Vulnerability.” An attacker with no login can view sensitive information over the network. The CNA score is CVSS 3.1 base 7.5, high. The record’s public date is 22 January 2026. Capsule’s dates are tighter. They found it on 24 November 2025 and reported it on 26 November. Microsoft confirmed it on 5 December 2025. Capsule says the fix deployed on 15 January 2026. Public disclosure was 15 April 2026. In their test the list held name, address, and phone.
This page does not reprint their sample. It used a fake system role and an outside mail address. The marker [PLACEHOLDER INSTRUCTION] is enough. The bug is the join of form text and the system task. Keep the form field in a data block the task cannot rewrite. Do not let that agent send external mail. Give it the smallest list scope. The January 2026 fix closes the path Microsoft confirmed. It does not close the class.
In all three, a stranger writes a form, the product stores it, and an agent with private rows and an outbound tool reads it.
What does a prompt injection real life example look like?
Each channel below is one hop, one sink, and one stop. The instruction is always [PLACEHOLDER INSTRUCTION]. None of these is a payload you can run.
A prompt injection example on a website
A browsing agent summarizes a page. The page holds visible text plus the marker, often where a person does not look. If the agent can open links, the sink is https://attacker.example/log. Unit 42’s ad review used a verdict as the sink. Greshake’s 2023 Bing Chat demo is the same channel. Fetch the page as data, strip hidden text, and block any URL the model invents.
The owner asks for a summary of new mail. The bad message is already in the inbox. EchoLeak needed no click. Gemini needed the Summarize button, and the sink was the summary text. Shortwave could fire from “find urgent mail” without opening the bad message. Keep read tools away from send tools. Do not render images or links the model writes. The hiding tricks and the defensive code are in Indirect Prompt Injection via Email.
A form
The marker rides in the message field from the first section. The CRM or the form backend stores it. The agent reads it on a later summary. ForcedLeak, PipeLeak, and ShareLeak are this hop. Give that agent a read token and no send tool. A person approves any mail, and the server checks the recipient.
A GitHub issue
Invariant Labs showed this on 26 May 2025. A public issue holds the marker. One GitHub token can also read a private repo. The agent opens a public pull request that contains the private text. This is not a bug in the MCP server code. GitHub cannot patch it alone. Use one repo per token. The test used Claude Desktop. Any client with that token is in scope.
A tool description
A tool description can hold the marker. The model reads it when the tool loads. What tool poisoning in MCP is, with a scanner you can run covers that metadata. A later edit, after you approved a calm list, is an MCP rug pull. The pin and the block are in MCP Rug Pull Attack: Detect Tool Changes. Show the full description before the first approval, then hash it.
The pattern behind every example
Every row above is the same shape. Simon Willison calls it the lethal trifecta (16 June 2025). You need all three:
- Untrusted channel. A page, an email, a form, an issue, or a tool description that an attacker can write.
- Private data. Mail, CRM rows, a private repo, or a SharePoint list the agent can read.
- Outbound sink. An image URL, an email, a pull request, a link, or a verdict the model can set.
Remove one leg and that leak path stops. The easiest leg to remove is the sink. A summary job does not need a send tool. Willison’s post uses the GitHub MCP case, where one server held all three. Which leg to remove for a form agent is on step-by-step prevention with a TypeScript policy layer.
Approval prompts are a weak fourth control. Anthropic published the figure on 25 May 2026. “Our telemetry showed users approved roughly 93% of permission prompts.” More prompts mean less attention to each one. The gates that held sat outside the model. Those gates are no egress, no send tool, a current URL allow list, or a token that cannot reach the private store.
Ai agent prompt injection examples keep showing up because one session holds all three legs. The definition stays on Indirect prompt injection in MCP. A prevention guide is not live on this site yet, so this page does not link one.
Where are indirect prompt injection examples on GitHub?
Searches for indirect prompt injection examples github want a repo. Three public ones were reachable on 06.10.2026. This page does not copy their strings.
- OWASP AITG-APP-02 is a test in the OWASP AI Testing Guide. It says what to look for when a model reads outside text. It is a test plan, not a kit.
- BIPIA is Microsoft’s benchmark. The paper is arXiv:2312.14197. The repo is lab data, not a list of CVEs.
- greshake/llm-security is the code companion to the February 2023 paper. Treat it as history, not as a script.
A cheatsheet of attack strings also ranks. This page does not link it. For a lab, use BIPIA or AITG-APP-02, and keep the model off your real mailbox. In notes you share, use only [PLACEHOLDER INSTRUCTION].
Prompt injection example 2026 is not one repo. The 2026 rows here are ShareLeak, PipeLeak, and Anthropic’s approval figure.
What Formgong does about this
Formgong is a free form backend for static and AI-built sites that delivers submissions to Telegram and email, stores data in the EU, and works in 12 languages. On the free plan, Telegram is instant and email arrives as a daily digest. Paid plans can mail per submission. A form backend does not make prompt injection impossible. It can refuse to be the send tool.
The MCP server, checked on 06.10.2026, matches llms.txt. Sign-in uses authorization code and PKCE S256. The token is bound to this resource. Session cookies do not authorize the MCP endpoint. Scopes are forms:read, forms:write, and submissions:read. Reading submissions is opt-in. The read tool says visitor fields are untrusted data, never instructions. The tool result repeats that notice. There is no MCP tool that sends mail, deletes a row, or writes a sheet.
That notice is a label, not a boundary. A mailbox or a browser in the same chat is not Formgong’s token. The submission text is still in the context. Plans are on the pricing page. Other backends are on the comparison hub. For a security issue, write to support@formgong.com.
Frequently asked questions
Where does an indirect prompt injection example come from?
A stranger hides an order in a web page, an email, a form, an issue, or a tool description. An agent reads that text while doing a normal job and can follow the order. The attacker never types in the chat. Named cases on this page include EchoLeak, ForcedLeak, and ShareLeak. The sample uses only the marker [PLACEHOLDER INSTRUCTION].
Which public GitHub repos document indirect prompt injection?
OWASP AITG-APP-02 is a test plan. Microsoft’s BIPIA repo is a research benchmark, with paper arXiv:2312.14197. greshake/llm-security is the code companion to the 2023 paper. This page does not copy the strings in those repos.
What is EchoLeak?
EchoLeak is Aim Labs’ name for CVE-2025-32711, a zero-click indirect prompt injection in Microsoft 365 Copilot. A malicious email could steer Copilot into leaking context through an image URL. Microsoft said no customer was affected, and the fix was rolled out before the 11 June 2025 public note.
What is an Agentforce prompt injection?
ForcedLeak and PipeLeak both used a public Salesforce lead form. ForcedLeak, scored 9.4 by Noma, leaked through an image URL until Trusted URLs on 8 September 2025. PipeLeak, disclosed 15 April 2026, used an email tool. Salesforce did not assign PipeLeak a CVE.
Sources and documentation
Official references for this guide: Greshake et al., arXiv:2302.12173 (published 23 February 2023), Liu et al., HouYi, arXiv:2306.05499 (published 8 June 2023), CVE-2024-5184, Invariant Labs: GitHub MCP toxic agent flow (26 May 2025), Aim Labs EchoLeak write-up (Cato Networks), Simon Willison: EchoLeak note (11 June 2025), CVE-2025-32711, 0DIN: Phishing For Gemini (10 July 2025), Insinuator: stealing emails via prompt injections (2 September 2025), Noma Labs: ForcedLeak (25 September 2025), Unit 42: indirect prompt injection in the wild (15 December 2025 note), Unit 42: web-based indirect prompt injection, Capsule Security: ShareLeak, CVE-2026-21520, CVE-2026-21520, CSO Online: form-based prompt injection (15 April 2026), Capsule Security: PipeLeak (disclosed 15 April 2026), Anthropic: how we contain Claude (25 May 2026), Simon Willison: the lethal trifecta (16 June 2025), OWASP AI Testing Guide, AITG-APP-02, Microsoft BIPIA benchmark, Yi et al., BIPIA, arXiv:2312.14197, Greshake et al. code companion. Formgong MCP server, where data is stored.
Read this article as MarkdownRelated guides
- Lovable form submissions to email and Telegram
- HTML contact form without a backend: a working example
- How to send website form submissions to Telegram
- Contact form not sending email? Check where it stops
- Managing website leads in Telegram without a CRM
- Form backend for Lovable, Bolt, v0, Cursor
- Telegram bot for a contact form: build or skip?
- GDPR form backend: 7 checks before you choose
- Lovable form not sending email? 6 fixes
- Netlify Forms not working? React and Bolt fixes
- Stop contact form spam without a CAPTCHA
- GitHub Pages contact form: a working setup
- Mailto Form in HTML: Why It Fails and What to Use
- HTML form to Google Sheets: 2 free methods
- Webflow form submission limit: what to do at 50
- Turnstile vs reCAPTCHA vs hCaptcha for forms
- Contact Form 7 and Elementor forms to Telegram
- Squarespace contact form not sending email?
- Shopify contact form: where do messages go?
- Google Form to Telegram: free Apps Script way
- Wix contact form not sending email? Fixes
- EU / GDPR Formspree alternatives compared
- HTML form action attribute explained
- How do HTML forms work? The HTTP request
- Types of Injection Attacks on Web Forms (2026)
- Indirect Prompt Injection in MCP
- MCP Rug Pull Attack: Detect Tool Changes
- Form without a backend: 7 ways that work
- Thank-you page after form submission (HTML)
- Indirect Prompt Injection via Email
- What Is Tool Poisoning in MCP?
- WordPress contact form without a plugin
- Send email from frontend JavaScript
- How to Prevent Indirect Prompt Injection
- Honeypot Form Field: How to Add One That Works
- Contact Form with File Upload (HTML, No PHP)
- Angular contact form without a backend
- Send form submissions to Slack or Discord without Zapier
- Verify a form webhook signature (HMAC-SHA256)
- Contact forms that send nothing: 793 AI-built sites tested
- v0 contact form that actually sends: 3 ways
- How we tested AI-built contact forms, and 12 bugs we hit
- Cloudflare vs Netlify free plan: hosting that never pauses
- EmailJS errors 400, 412 and 422: causes and fixes
- Resend errors in contact forms: domain, CORS, API key
- Supabase Edge Function blocked by CORS policy: 3 causes
- Formspree “Form not found” and other errors: fixes
- Web3Forms errors: “Invalid access key” and 403 explained